The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Add the second condition with OR comparisons

Prev Next

Steps to add the second condition to the example signature:

  1. In the Signature Details section, click GUID-F3F18CF8-B95D-4C8C-8DB8-996CDB6087FB-low.png to add the condition.

    The first condition is minimized and the second condition reads as [AND THEN] Condition 2, thus signifying the first condition must match before the second condition can be tested.

    Adding conditions
    Adding conditions


  2. Select the text of the second condition, click GUID-B4864D1C-95C3-4825-96BA-EAE9E98FDAC8-low.png.

  3. Select Numeric Value Match from the Comparison Type drop-down list.

  4. Select http from the Protocol list.

  5. Select req-uri-length for the Protocol Field, then get as the request method.

  6. Select Greater than from the Operator drop-down list.

    Configure Comparison window to select the comparator
    Configure Comparison window to select the comparator


  7. (Optional) Check the Signed check box if you want the value to be signed.

  8. Type a length value in the Value to Match field. For this example, type 200 (bytes) as the length over which this comparison will match.

  9. Click Save; you are returned to the New Signature window.

  10. Verify that your newly added comparison appears under Condition 2 under the heading [AND Then].

    View the new condition defined
    View the new condition defined


  11. Click on Condition 1, then click GUID-B4864D1C-95C3-4825-96BA-EAE9E98FDAC8-low.png under Comparisons.

  12. Select Numeric Value Match from the Comparison List.

  13. Select http from the Protocol.

  14. Select req-header-length for the Protocol Field, select content-length as the http-req-hdr-type, then select get as the http-req-method.

  15. Select Greater than from the Operator drop-down list.

  16. Type a length value in the Value field. For this example, type 1 (byte) as the length over which this comparison will match.

    Note

    As stated in the Description field, a value of 1 byte is significant for this comparison as the normal header length of a request should be zero.

    GUID-ED7C4EFC-0849-46B8-8102-41BFE1C74BF4-low.png
  17. Click Save; you are returned to the New Signature window.

  18. Verify that your newly added comparison appears beneath the first comparison you configured for Condition 2. The second comparison line is preceded by [OR] to signify the either-or relationship between the two comparisons.

    GUID-0F9285F9-F54F-4B98-91F2-F2C0FCF78E61-low.png
  19. Click Update in the signature details window.

    Note

    Though there are multiple conditions and comparisons, only one signature was created; so only one signature is uploaded to the Manager.

  20. Verify that the attack definition is listed on the Native Trellix IPS Format tab.

  21. Click Save to save the Trellix IPS Custom Attack in the Manager server database.

  22. Make sure the Trellix IPS Custom Attack is saved in the database and also published in the policies.