We are pleased to announce that Trellix Helix 2026.1 has been successfully deployed across all regions. This release delivers significant enhancements across analyst workflows, detection coverage, Hyperautomation capabilities, and platform visibility, all aimed at reducing mean time to investigate and respond.
Below is a summary of what is new and available to you today.
Alert investigation
-
AI-powered alert summaries with Trellix Wise
-
Wise alert summary: Trellix Wise now uses AI to summarize alerts, assess their potential impact, and explain how severity is determined—including information on malicious events, impacted users, and source IP addresses. It is available on the Summary tab in Alert Details and on the side panel in the Alert List page.
-
Wise alert summary: Trellix Wise now uses AI to summarize alerts, assess their potential impact, and explain how severity is determined—including information on malicious events, impacted users, and source IP addresses. It is available on the Summary tab in Alert Details and on the side panel in the Alert List page.
-
Enhanced alert timeline
- Rule context in timeline: The alert timeline now surfaces the rule that generates the alert, including the match condition responsible for the detection, available in the Rule Details tab of the side panel.
-
Investigative tips and recommended queries: The alert timeline now shows investigative tips and contextual queries with associated TQL search queries that you can run directly to enrich alert context.
-
Enhanced alert asset details
-
Asset tab enrichment: The Asset tab now displays each asset with relevant details alongside its associated alert or event, and the containment status. Inline remediation actions such as blocking an IP address or isolating an asset are available directly from the actionable drop-down of the asset.
-
Asset tab enrichment: The Asset tab now displays each asset with relevant details alongside its associated alert or event, and the containment status. Inline remediation actions such as blocking an IP address or isolating an asset are available directly from the actionable drop-down of the asset.
-
Bulk actions on alerts
-
Bulk acknowledge and assign: You can now acknowledge or assign alerts in bulk. Actions apply to the current page or to all matching alerts.
-
Bulk acknowledge and assign: You can now acknowledge or assign alerts in bulk. Actions apply to the current page or to all matching alerts.
-
Alert data retention in cases
- Extended retention: Alerts linked to cases are now retained beyond the standard 90-day window. A read-only version of the alert and its events remains accessible for up to 13 months after the alert is generated, supporting both ongoing investigation and audit requirements.
Case management and search
-
Case workflow improvements
- Add alerts to a case: Alerts can now be added to a case from the Related Alerts tab, adding context and reducing mean time to investigate.
-
Add events from Search: Search results can now be added to a new or existing case directly from the Search page, enriching investigation context without pivoting.
-
Search enhancements
- TQL search hints: As you type a TQL query, Helix now suggests color-coded fields inline. Selecting a function surfaces its description and required syntax. Common examples are also shown on the Search page.
- Search result count: The number of results for each recently run search is now displayed on the Search Activity page.
Rule management
-
Real-time rule syntax validation: The rule builder now validates YAML schema, data types, regular expressions, and correlation/cardinality/deviation conditions as you type.
-
Muted alerting: Rules can now be set to Muted status, allowing you to monitor rule performance over time without surfacing alerts in the default alert table. Muted alerts and rules are accessible via the Status filter.
- Federated rule creation (MSSP): MSSP customers can now select a specific tenant when creating a rule from a search query in federated view.
Hyperautomation
-
Custom Respond integrations: Create and manage custom Respond integrations directly from the Integration Hub.
-
Tasking via alerts: Hyperautomation tasks, to execute single step actions, can now be triggered from Alerts Summary > Respond and Assets tab. You can also view the available tasks and their associated integrations from the mega menu.
- Quota visibility: The UI now displays warnings at 70%, 90%, and 100% of your allowed daily Hyperautomation workflow execution quota.
Platform
-
Entitlements dashboard: Customers on Helix Essentials, Core, or Enterprise SKUs can now view their pricing model, entitlements, and current ingest usage on the new Entitlements dashboard.
- CIDR allow list (Trellix IAM): - Admins can now configure a CIDR allow list on Trellix IAM to restrict Helix tenant access based on user IP address. Only IPV4 is allowed.
Detections
-
Living off the land – Binaries: Expanded detection capabilities to identify the exploitation of schtasks.exe and rundll32.exe.
-
Living off the Land – C2 frameworks: Broadened coverage for detecting the exploitation of C2 platforms, such as HuggingFace.
-
Living off the Land – RMM tools: Expanded detection coverage for remote monitoring and management tools: AnyDesk, LogMeIn, Splashtop, Atera, FleetDeck, and BlueTait.
- Enterprise coverage: Enhanced detection logic for Okta, Distributed Component Object Model (DCOM) techniques, and new Trellix ENS integration coverage.
Additional row grouping and column filtering capabilities for tables have been included. Explore these features in Helix ‘New’ Apps.
You can find more information about Helix Connect in our Product Guide and Release Notes:
Trellix Helix 2026.1 is available automatically on the platform.