The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add the condition for numeric range match

Prev Next

Steps to add the condition to the example signature:

  1. Click Condition 1 so that it is highlighted.

  2. Click AND in the Comparisons section.

    The Add AND Comparision dialog opens.

    Numeric Range Match
    Numeric Range Match


  3. For this example, select Numeric Range Match in the Comparison Type drop-down menu.

  4. Select http from the Protocol list.

    Because you selected HTTP, the Custom Attack Editor displays the http specific protocol fields on the screen.

  5. Configure the fields for the comparison you have chosen.

    For this example, specify dst-port for the Protocol Field. This specifies that the Sensor should search in the URI of the request packet.

  6. From the drop-down list in the Operator, select the matching criteria as Equals which means that the comparison criteria must be between to the minimum and maximum values entered.

  7. Type the minimum value in the Mininum Value field.

    For this example, the minimum value is "100".

  8. Type the maximum value in the Maximum Value field.

    For this example, the value to match is "2000".

  9. Click Save.

    Your comparison appears under Condition 1.

  10. Click Add in the New Custom Attack window.

  11. Verify that the attack definition is listed on the Native Trellix IPS Format tab.

    GUID-090220BF-AFED-4A29-AA90-3F75C171F710-low.png
  12. Click Save to save the Trellix IPS Custom Attack in the Manager server database.

  13. Make sure the Trellix IPS Custom Attack is saved in the database and also published in the policies.