The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add the condition

Prev Next

Steps to add the condition to the example signature:

  1. Condition 1 is added automatically according to the URL you provided.

  2. Click Condition 1 so that it is highlighted.

    GUID-165E33B8-B877-48B2-9918-53D520DCA906-low.png
  3. Click AND in the Comparisons section.

    The Add AND Comparison dialog opens.

  4. For this example, select String Pattern Match in the Comparison Type drop-down menu.

  5. Select http from the Protocol list.

    Because you selected HTTP, the Custom Attack Editor displays the HTTP-specific protocol fields on the following screen.

  6. Configure the fields for the comparison you have chosen.

    For this example, specify req-uri-path for the Protocol Field. This specifies that the Sensor should search in the URI of the request packet.

  7. Select get as the http request method.

  8. From the Operator drop-down list, select the matching criteria as Equals which means that the comparison criteria must be equal to the regular expression entered.

  9. Type the pattern to match using the Text to Match.

    For this example, the pattern to match is either "cgi.bin/trillion.pl" or "cgi.bin/trilliant.pl", where "pl" is case-insensitive. To properly write this expression, use the following rules:

    • Add a backward slash (\) before every dot (.) to escape: cgi.bin = cgi\.bin

    • Use alternatives where possible. For this example, trillion and trilliant can be written as: trilli(on|ant).

    • Use character classes to denote case insensitivity for "pl": [Pp][Ll]

    The final string should appear as: cgi\.bin/trilli(on|ant)\.[Pp][Ll]

    Regular Expression details
    Regular Expression details


  10. Click GUID-1C393536-5E83-4665-9BCD-59D156B85B94-low.png to verify that your expression is a valid string, and all required options are represented. Click OK to close the validation message window.

  11. Click Save.

    Your comparison appears under Condition 1.

  12. Click Save in the Add Exploit Attack window.

  13. Verify that the attack definition is listed on the Native Trellix IPS Format tab.

  14. Click Save to save the Trellix IPS Custom Attack in the Manager server database.

  15. Make sure the Trellix IPS Custom Attack is saved in the database and also published in the policies.