The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add the condition for packet grep protocol match

Prev Next

Steps to add the condition to the example signature:

  1. Click Condition 1 so that it is highlighted.

  2. Click AND in the Comparisons section.

    The Add AND Comparison dialog opens.

    Packet Grep Protocol Match
    Packet Grep Protocol Match


  3. For this example, select Packet Grep Protocol Match in the Comparison Type drop-down menu.

  4. Select dnp3 from the Protocol list.

    Because you selected IPv4, the Custom Attack Editor displays the IPv4-specific protocol fields on the following screen.

  5. Configure the packets you want to parse.

    For this example, specify Request Packets Only for the Parse field.

  6. From the Operator drop-down list, select the matching criteria as Equals.

  7. Type the text you are searching for in the packets in the Text to Match.

    For this example, the text to match is " \x00\x00\x00\x3a\x20\x45\x56\x00\x0a".

  8. (Optional) Deselect Ignore Case and Ignore String Position.

  9. Click Save.

    Your comparison appears under Condition 1.

  10. Click Add in the New Custom Attack window.

  11. Verify that the attack definition is listed on the Native Trellix IPS Format tab.

    GUID-70AEEE04-2EFB-46C6-B802-EC062D2FCF28-low.png
  12. Click Save to save the Trellix IPS Custom Attack in the Manager server database.

  13. Make sure the Trellix IPS Custom Attack is saved in the database and also published in the policies.