Maintaining rules

Prev Next

A rule in Helix Enterprise is a TQL search query that is run automatically. In a rule, you can specify thresholds, windows, and distinguishers that control when alerts are generated. When a rule locates a match (a “hit”), it generates an alert or a log entry, depending on its configuration. Helix Enterprise supports single-stage and multistage rules. Multistage rules contain rules that work together to detect complex threats.

There are two types of rules in Helix Enterprise:

  • Trellix rules: Rules created by Trellix experts that detect a wide range of malicious activity. These rules are created and updated regularly.

  • Customer rules: Rules that you define, which detect events specific to your environment and organizational needs.

You can group related rules into rule packs, which let you organize your rules, as well as enable and disable the rules as a group. For more information about rule packs, see Using rule packs.