The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Attack Definitions tab

Prev Next

The Attack Definitions tab lists the inbound and outbound attack definitions included in the IPS Policy. An IPS Policy typically contains thousands of attack definitions. So, the Attack Definitions tab has some useful filtering options to locate attack definitions.

To set the display of attack definitions click on the column header and then select or type in the Filters options. There are two options to filter the displayed attack definitions: List based filter and String based filter.

List based filter is available for those columns where the display of attack definitions is based on selecting a specific criteria listed in the column.

String based filter is available for those columns where the display of attack definitions is based on the criteria typed in the text field of the Filters option. By typing the first few characters in the text field, the policy assignments matching the typed characters are displayed on the page.

Note

When the attack definitions are displayed by using the Filters option, the header of column by which the policy assignments are filtered is highlighted in orange color. By clicking the Clear All Filters button, the filter is removed and all the attack definitions are displayed on the page.

Attack Definitions tab
Attack Definitions tab


Click a column header and select the option to sort based on ascending or descending order. The options are Sort Ascending and Sort Descending.The column based on which the list is sorted is indicated in the column header by an up arrow icon for ascending order and down arrow icon for descending order.

Sorting and Grouping options
Sorting and Grouping options


For a consolidated view of a group of the attack definitions, click on the column header of the field (Example : Severity) by which it should be grouped and click Group by this field.

Note

To remove the display of attack definitions by groups unselect the Show in groups check-box option from the column header. The Show in Groups option is enabled only if the Groups by this field option is selected.

All fields can be sorted, except the following:

  • Industry IDs(All)

  • Protocols

  • Sensor Actions

  • Manager Actions

All fields can be grouped, except the following:

  • Industry IDs(All)

  • Protocols

  • Name

  • Protection Category

You can search for an attack based on the criteria typed in the text field of the Quick Search option. By typing the first few characters in the Quick Search text field, the attacks matching the typed characters are displayed on the page. By clicking the Clear All Filters button, the filter is removed and all the attacks are displayed on the page.