The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Attack categories and severity range

Prev Next

Trellix IPS categorizes attacks into four groups: Reconnaissance, Exploits, Volume DoS, and Policy Violation. The following table illustrates how severity levels are assigned for attacks in different categories.

Category

Threat type

Severity Level

Attack Description

Reconnaissance

Host sweep

4-4

A well-defined sequence of packets covering a range of destination IP addresses or ports, that aims to identify live hosts or open ports on the target host.

Traffic activities that indicate interactive shells under operating systems like Unix or Windows.

Port scan

4-4

Brute force

4-6

Alerts that indicate that someone is making repeated attempts at an authorization or information query service like POP3 and IMAP logins and invocation of SMTP VRFY commands. Such events suggest possible reconnaissance activities for targeted attacks.

Activities related to running network applications that are forbidden by policy such as running an IRC or music share server on the corporate network without authorization.

Activities suggesting that a standard protocol is run over non-standard ports.

Service sweep

6-6

A well-defined sequence of packets, each of which is a probe attempt itself, launched against a given destination IP address that aims at identifying the target operating system or host type.

A well-defined traffic that crossed the thresholds like ICMP packet rate, IP fragment rate, etc.

A well-defined sequence of packets covering a range of destination IP addresses, and aims at identifying hosts with a particular service.

OS Fingerprinting

6-6

Exploits

Probe

2-2

Alerts that probe on a specific service or host, based on specially constructed packets, for example, unusual flag settings.

Protocol Violation

3-5

Unusual application protocol behaviors that includes invalid field values or invalid command sequences etc.

Packets that are well crafted, for example, with invalid or inconsistent TCP/UDP/IP header values, aiming to crash the target TCP/IP stack or to cause high resource consumption.

Any network event or payload that is specifically related to virus. A malicious virus can inflict many different types of damages to its target, ranging from stealing or destroying information to installing backdoor processes. However, a virus relies on other carriers like e-mail, to gain access the network.

A successful attack, that suggests that a breach of confidentiality has occurred. Examples include directory traversal, dump of file content such as CGI script, or reading other sensitive data files such as password and database records.

DoS

3-5

Virus

3-5

Read Exposure

3-5

Trojan

3-9

Alerts that indicate Trojan activities like communication, installing, downloading, and the alerts that indicate malware detected through GTI File Reputation and/or custom fingerprinting.

Write Exposure

5-7

A breach of integrity or authenticity of data like the creation or removal of files and modification of files for system configuration or user passwords. There is often a severe indirect impact, for example, a breach of access control by adding an illegal user account.

These are content keyword matches that are deemed to indicate transmission of sensitive information such as a document with the marking "Company Confidential".

Remote Access

5-9

Remote access that potentially indicates a successful exploitation where unauthorized access is obtained. For example, a successful buffer overflow on a Windows server may open a windows command shell for the attacker. An attacker may be able to perform further attacks to achieve privilege elevation once remote access is obtained.

The attempts can be either contacting backdoor process or occurrence of actual backdoor 2-way conversation.

Evasion Attempt

7-7

Alerts that indicate a sequence of packets or bytes in the traffic, signifying specific attempt at evading IDS.

Large volume of traffic, that is valid from the perspective of an application content that can overwhelm processing element along the target path including switches, routers, firewalls, target servers etc.; this will cause an effect of DoS on other legitimate traffic.

Code/Script Execution

7-7

Bot

7-9

These kinds of alerts indicate attempts to exploit software vulnerabilities where manipulation of buffer spaces can result in overwriting of unintended memory areas. Such overwriting can have different consequences depending on whether the areas are executable or not. If not, it can cause malfunction of the software.

These kinds of alerts indicate the most severe form of buffer overflow attacks that is, a buffer overflow attack carrying shellcode payload. Shellcode is a general term used for a piece of executable code that, upon successful execution on the target system, will modify the target's configuration or behavior for malicious purposes.

Depending on the confidence level of the triggers, it can either be some attempts at contacting backdoor process or occurrence of actual backdoor 2-way conversation.

Shellcode Execution

7-9

DDoS Agent Activity

7-9

Backdoor

7-9

Buffer Overflow

7-9

Worm

6-9

Any network event or payload related to worm activities. A malicious worm can inflict many different types of damage on its target, ranging from stealing or destroying information to installing backdoor processes.

Privileged Access

8-9

An unauthorized access to privileged accounts is obtained such as a successful buffer overflow on a UNIX server may open a root shell for the attacker. Alternatively, the attacker may have achieved successful privilege elevation from a legitimate user account, or from a remote access compromise.

Privileged access allows the attacker to take complete control of the compromised system.

Arbitrary Command Execution

8-8

Alerts that indicate attempts to execute arbitrary commands on the target machine. For example, an IIS vulnerability may allow remote invocation of cmd.exe to execute any other Windows commands.

Volume DoS

Statistical Deviation

7-7

Alerts that indicate a sequence of packets or bytes in the traffic, signifying specific attempt at evading IDS.

Large volume of traffic, that is valid from the perspective of an application content that can overwhelm processing element along the target path including switches, routers, firewalls, target servers etc.; this will cause an effect of DoS on other legitimate traffic.

Over Threshold

6-6

A well-defined sequence of packets, each of which is a probe attempt itself, launched against a given destination IP address that aims at identifying the target operating system or host type.

Policy Violation

Audit

0-0

It is reserved for those attacks and conditions that is not determined to fit accurately into any of the specific categories currently defined.

Any networking event deemed to be of interest to the security analyst such as invocation of particular applications or use of a particular command in certain applications.

Restricted Access

4-5

Any activity related to usage of network resources that are explicitly forbidden. For example, emails sent to or received from a particular address.

Restricted Application

4-5

Unauthorized IP

5-5

Any traffic activity that suggests an existence of IP address that is not authorized for the protected network.

Communication activities that are deemed unintended but the communication channel being monitored.

Covert Channel

5-5

Sensitive Content

5-7

A breach of integrity or authenticity of data like the creation or removal of files and modification of files for system configuration or user passwords. There is often a severe indirect impact, for example, a breach of access control by adding an illegal user account.

These are content keyword matches that are deemed to indicate transmission of sensitive information such as a document with the marking "Company Confidential".

Command Shell

4-4

A well-defined sequence of packets covering a range of destination IP addresses or ports, that aims to identify live hosts or open ports on the target host.

Traffic activities that indicate interactive shells under operating systems like Unix or Windows.

Non-standard Port

4-4

Phishing

1-3

Potentially an unwanted program that may include a malware, adware or any other program.

Potentially Unwanted Program

Malware

Malware

4-9

Alerts that indicate a malicious file transfer is detected on network by Trellix ARC.