You can detect and alert on TCP protocol anomalies and check to TCP session hijacking using the Stream5 preprocessor variable.
On the Trellix ESM console, click the Policy Editor icon
.In the Rule Types pane, click Variable.
In the Variables pane, expand the preprocessor group, then double-click STREAM5_TCP_PARAMS.
On the Modify Variable page, add one of the following in the Value field:
To detect and alert on TCP protocol anomalies, add
detect_anomaliesafter policy first.To check for TCP session hijacking, add
detect_anomalies check_session_hijackingafter policy first.