The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

About IPS detection of brute-force attacks

Prev Next

A brute-force attack is a trial-and-error method used to obtain unauthorized access to resources. An IPS platform detects repeated failed login attempts as well as common password-stealing and password-guessing mechanisms, such as dictionary attack. By analyzing the pattern and volume of activities and hosts, the IPS-enabled rules engine can distinguish between brute force attacks and valid network traffic. The platform triggers a brute-force event when the number of failed login attempts to or from the same IP address reaches a certain threshold within a 60‑second rolling window. You can configure the number of failed login attempts that triggers a brute-force event. For details, see Configuring the detection threshold for brute-force attacks (CLI).

Brute-force detection is enabled if an active IPS policy selects one or more IPS brute-force rules.

IPS brute-force events do not trigger FireEye event notifications and cannot be acknowledged.

Protocol ports supported

The IPS-enabled rules engine detects brute-force attacks by applications that use ports for the following protocols. The list is dynamic, and Trellix controls the list through periodic updates of IPS security content.

  • IPv4 FTP

  • IPv4 Mysql

  • IPv4 Postgress

  • IPv4 rsh

  • IPv4 SMB

Additional protocol ports supported in detailed inspection mode

To protect additional protocol ports from brute-force attacks, you can enable the IPS rules engine to operate in detailed inspection mode. In this mode, the rules engine performs a more detailed inspection of packets than it does when operating in default mode. The list of protocol ports that require detailed inspection mode is dynamic, and Trellix controls the list through periodic updates of IPS security content.

At the time of this release, detailed inspection mode enables the platform to detect brute-force attacks by applications that use ports for the following protocols:

  • IPv4 Telnet

  • IPv4 VNC

  • IPv4 rlogin

  • IPv6 Telnet

  • IPv6 FTP

Caution

IPS detailed packet inspection may slow IPS processing.