The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add the first condition and comparison for your signature

Prev Next

Steps to add the condition to the example signature:

  1. Condition 1 is added automatically with the URL.

  2. Click Condition 1 so that it is highlighted.

    Adding Conditions
    Adding Conditions


  3. Click GUID-621EB179-B0A5-43D9-99A3-64CB0BB6FB20-low.png in the Signature Details section.

    The Add AND Comparison dialog opens.

    Configure Comparison window
    Configure Comparison window


  4. For this example, select String Pattern Match from the Comparison Type drop-down list.

  5. Select http from the Protocol List.

    Because you selected HTTP, the Custom Attack Editor displays the HTTP-specific protocol fields on the following screen.

  6. Configure the fields for the comparison you have chosen.

    For this example, specify req-uri-path for the Protocol Field. This specifies that the Sensor should search in the URI of the request packet.

  7. Select get as the http-request-method.

  8. From the drop-down list in the Regex Details section, select the Operator as Equals which means that the comparison criteria has to be equal to the string pattern entered.

  9. In the Text to Match text box, type the pattern to match using the Regular Expression Language rules.

    The pattern to match is "private.exe". You must add a backward slash (\) before the dot (.) to escape the dot character so that it is properly interpreted. The final string should appear as private\.exe.

    Adding the string pattern to match
    Adding the string pattern to match


  10. Click GUID-1C393536-5E83-4665-9BCD-59D156B85B94-low.png to verify that your expression is valid, and that the appropriate pattern is represented.

  11. Click Save.

    Your comparison appears under Condition1.