The following regular expression constructs are not supported in Trellix Helix rules as of TQL 3.0:
Back references and capturing sub-expressions
Arbitrary zero-width assertions
Subroutine references and recursive patterns
Conditional patterns
Backtracking control verbs
The \C "single-byte" directive (which breaks UTF-8 sequences)
The \R newline match
The \K start of match reset directive
Callouts and embedded code
Atomic grouping and possessive quantifiers