Trellix Helix 2026.1

Prev Next

The Trellix Helix 2026.1 release includes new features and enhancements. For more information, see the Helix Product Guide.

New features and changes

Monitor usage on the Entitlements dashboard

Customers with the Helix Essentials SKU, or the Helix Core SKU, or the Helix Enterprise SKU can see which pricing model you are on, the entitlements that are part of that model, and your current usage on the Entitlements dashboard. For more information, see Entitlements dashboard.

Use search hints to create TQL queries

To help you create TQL search queries, Helix suggests color-coded fields as you type. Select a function to see what the function does and the required syntax. The Search page also shows basic TQL syntax and common search examples. For more information on TQL, see the Trellix Helix TQL Reference Guide.

Investigative tips and recommended search queries

The alert timeline shows investigative tips. These are a list of questions and associated search queries you can run to enrich the alert with contextual information. For more information, see Understanding alert activity using the Alert Timeline.

Creating custom Respond integrations

Create new custom Respond integrations, and manage existing ones, from the Integration Hub. If a product is not listed in the Integration Hub, you can create a custom Respond integration on the Integration Hub > Custom Integrations page. For more information, see Create a custom Respond integration.

Monitor Hyperautomation quota

The UI displays a warning when you reach 70%, 90%, and 100% of your allowed daily quota of workflow executions. The quota includes all types of executions: manual, scheduled, test runs, sub-workflow, and auto-triggered.

Tasking with Hyperautomation

Map Hyperautomation tasks to alerts. Open an alert, select the Respond tab, and add tasks to perform specific actions on the alert. For more information, see Run a task on an alert.

Monitor Ingestion quota

The UI displays a warning when you exceed your daily ingestion quota.

Enhanced alert information with Trellix Wise

Trellix Wise use AI to summarize alerts, assess their impact, and explain how the severity was determined. It provides information on malicious events, impacted users, and source IP addresses. For more information, see Get an overview of the alert on the Summary tab.

Enhanced alert timeline

The alert timeline shows information about the rule that generated the alert. Each alert shows the rule parameters groupby, require, and within. Select the alert to open a side panel, then select the Rule Details tab to see the rule condition. This means you don't have to pivot to the rule page for important contextual information.

Enhanced alert asset details

The Asset tab shows each asset, the alert or event associated with it, and the containment status of the asset. Click the arrow next to each asset to perform remediation actions, for example to block an IP address or isolate an asset. Click the name of the alert or event to pivot to the timeline to better understand the attack flow.

Adding alerts to a new case

You can add alerts to a case on the Related Alerts tab of the case. This adds context to the case and reduces the mean time to investigate. For more information, see Add alerts and artifacts to an existing case.

Validating rule syntax

When you create or edit a rule, Helix validates the rule as you type. It looks for errors in the YAML schema, validates data types, some regular expressions, for example within: 3h. It also validates the fields, correlation, cardinality, and deviation conditions.

Creating a rule from a search query in federated view

If you are an MSSP customer and you want to create a new rule from a search query, you can select which tenant you want to apply the rule to. For more information, see Create a rule from a search query.

Filtering columns for rules and correlated alerts

You can filter columns with the filter icon (HelixConnect-filter.png) on the rules page, and on the alerts page when you turn on the Correlated Alerts toggle. This allows you to quickly find and act on relevant information.

Grouping rows in the rules table

You can group certain columns in the rules table into rows to help you manage and analyze data. Where available, in the column header, select More Options (more-options.png) > Group by.

Creating a CIDR allow list on Trellix IAM

Admins can create a CIDR allow list for Helix tenants on the Trellix IAM. This restricts access to Helix based on a user's IP address. For more information, see Add CIDR allow lists.

Enabling rules for muted alerting

When you create custom rules, you can set the status to Muted. This allows you to evaluate the performance of the rule over time, without showing alerts by default in the alert table. To view muted alerts in the alert table, select Muted from the Status menu.

Taking bulk actions on alerts

You can acknowledge or assign alerts in bulk to save time. You can apply the action to alerts on the current page, or apply it to all the alerts. If you select fewer than 1,000 alerts, the update happens in real time. If you select more than 1,000 alerts, the update happens in the background and you cannot perform the action again until the process is finished.

Retaining alert data in cases

In Helix, alerts are retained for 90 days. For alerts that are added to a case, after 90 days a read-only version of the alert and its associated events remains available until 13 months after the alert was generated. This allows you to see the full context of a case after 90 days, as well as retaining this information for audit purposes.

Adding events to a case from search

You can add events from search results to a new or existing case. This adds context to your investigations. For more information, see Add search events to a case.

Displaying the number of search results

The number of results for each recently run search is shown on the Search Activity page.

Viewing the search results histogram

When you run a search, a histogram displays the results over time. Use the Search Visualization toggle to show or hide the histogram.

Changed behavior

You cannot disable or delete a Respond integration.

Supported languages

Trellix Helix supports English only.