The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Attack categories

Prev Next

When a system vulnerability has been discovered, an attacker can threaten the system with an attack that affects the system. The attack categories, also known as attack type, detail the general types of attacks that can be performed to a system.

Attack category

Description

Exploit

This category covers most attack activities that actively seek to compromise systems, gain unauthorized access to system or services, or tamper normal system operations by exploiting known or potential system vulnerabilities.

Malware

Malware is the short form for malicious software. It can be defined as a piece of harmful software code created and spread with a malicious intent. Examples are virus programs, Trojan horses, computer worms, spyware, and botnets.

In general, the objective of the attacks in this category is to steal system or user confidential information and send it back to the server controlled by the attacker. Targeted information includes user name, host name, user passwords, and license keys. Some other common characteristics of the attacks in this category include spamming, launching DoS attacks, downloading additional malicious code, and downloading updates to the malicious code.

Policy violation

An attacker performed an action that goes against the organizational or system policy, possibly by attempting to gain access they are not authorized to have. This includes all activities for which the underlying traffic content might not be malicious by itself, but are explicitly forbidden by the usage policies of the administrative domain. This includes application protocol behaviors that violate common usage practices.

Reconnaissance

This type of activities is for intelligence gathering to prepare for further attacks; for example, a port scan or probe conducted to enumerate or identify services and possible vulnerabilities.

DoS and DDoS

A denial of service (DoS) or distributed denial of service (DDoS) attack is performed, possibly harming the ability of the network or system to respond or continue providing services.

Multi Sensor correlation

Manager correlates the attack detection information from multiple intrusion detection systems (Sensors) to identify different phrases of the attack behaviors.

Protocol discovery

Sensor determines protocol anomaly on well-known ports, such as P2P software running on a well-known port.

Multi method correlation

Multiple detection methods are used to correlate the attacking traffic to identify different phrases of the attack behaviors. Examples of such correlation are attack signature, Trellix IPS shellcode detection, and statistical correlation.

Flow correlation

Sensor correlates the bi-directional traffic of each session to increase the accuracy of the attack detection as well as impact of the attack.

Application anomaly

This type of attack is caused when a large number of bytes comes from an HTTP browser than that are actually going onto it. An example of such an attack is Buffer Overflow.

Volume DoS

Large volume of traffic, which could be perfectly valid from the perspective of application content, that can overwhelm processing element along the path to the target including switches, routers, firewalls, target servers, and so on; this will cause a DoS effect on other legitimate traffic.