The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Attack subcategories

Prev Next

Attack subcategories are the specific, inherent system flaws that can be exploited by attackers familiar with a vulnerability or malware. A known vulnerability poses a threat to the system; the attacking party exploits this threat with an attack that is designed to affect some part of the vulnerable system. The following table captures some of the Attack subcategories:

Category

Description

Trellix Intelligent Sandbox

This kind of alert indicates that a malicious file transfer is detected on network by Trellix Intelligent Sandbox Engine.

Arbitrary Command execution

An attacker can execute system commands and scripts, like getting a directory listing on a system, thus stealing and destroying data. The attacker who is able to access a user's system can exploit the vulnerability and install malicious software and use the system to launch attacks on other systems.

Audit

Any networking event deemed to be of interest to the security analyst. Examples include invocation of particular applications or use of particular commands in certain applications.

Backdoor

Depending on the confidence level of the triggers, this can either be some attempts at contacting a backdoor process or the occurrence of actual backdoor two-way conversation. If the latter has occurred, it means that a backdoor process exists in your network, the backdoor user is in your network, or both are inside your network, depending on the locations of the communication endpoints.

Bot

It refers to a group of computers running or executing a program that allows an attacker to control the system remotely and make users execute commands like DOS. These commands are taken place in the IRC channel.

A 'bot' is a type of malware which allows an attacker to gain complete control over the affected computer. Computers that are infected with a 'bot' are generally referred to as 'zombies'. Attackers are able to access lists of 'zombie' PC's and activate them to help execute DoS (Denial of Service) attacks against Web sites, host phishing attack Websites or send out thousands of spam email messages.

A bot worm is a self-replicating malware program that resides in current memory (RAM), turns infected computers into zombies (or bots) and transmits itself to other computers. A bot worm may be created with the ultimate intention of creating a botnet that functions as a vehicle for the spread of viruses, Trojans and spam.

Botnet

It refers to a group of computers that has been infected by Bots in a network.

Brute Force

Brute force attacks are performed using programs, such as password crackers, to try different sets of passwords so as to guess the right one.

Buffer Overflow

This kind of alerts indicates attempts at exploiting software vulnerabilities where manipulation of buffer spaces can result in overwriting of unintended memory areas. Such overwriting can have different consequences depending on if the areas are executable or not. If not, it can cause malfunction of the software, thus denial of service; if yes, it can lead to execution of arbitrary machine code within the context of the current process which can lead to much more severe security breach.

Code/Script Execution

It refers to a vulnerability which can be exploited by malicious people to compromise a user's system. An attacker can execute malicious programs or code on a user's system.

Successful exploitation allows execution of arbitrary code and possibly takes complete control of the affected system. Attacker can run code with elevated permissions.

If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.

Command Shell

Traffic activities indicating interactive shells under Unix or Windows operating systems, and so forth

Covert Channel

Any communication activities that are deemed unintended by the communication channel being monitored

Custom Fingerprinting

It refers to the detection of malicious files using known hashes (MD5 or SHA256). MD5 and SHA256 hashes can be added to the Manager based on requirements.

DDoS Agent Activity

Known DDoS attack tools use various patterns of communication among attackers or handlers, and attacking agents or zombies. Detection of these activities is a good sign that either someone is attempting to contact DDoS agents, or there may be real attackers or agent processes in the monitored networks.

DoS

Well-crafted packets, for example, with invalid/inconsistent TCP/UDP/IP header values, aiming at crashing the target TCP/IP stack or causing high resource consumption.

Endpoint Intelligence Agent

This kind of alert indicates that a malicious file transfer is detected on network by McAfee Endpoint Intelligence Agent.

Evasion Attempt

This kind of alert indicates a sequence of packets or bytes in the traffic signifying a specific attempt at evading an IDS. For example, FTP attacks are known to use escape control character sequences to hide attack payload and TCP-based RPC attacks may use record format to split up attack payload.

File Mismatch

It refers to a file that has been given an extension which does not match its actual file type and/or content type. For example, a file with .exe extension (executable) downloaded with a text/plain content type.

OS Fingerprinting

Well-defined sequence of packets, each of which is typically a probe attempt itself, launched against a given destination IP address, typically aiming at identifying the target operating system or host type.

Gateway Anti-Malware

It refers to a malware that has been detected in a file analyzed by the Gateway Anti-Malware (GAM) advanced malware engine, which is the same Anti-Malware Engine found in Trellix Endpoint products, but it is optimized for network analysis.

GTI File Reputation

It refers to a malware that has been detected in a file analyzed by the Trellix Global Threat Intelligence.

Host Sweep

Well-defined sequence of packets sweeping through a range of destination IP addresses, typically aiming at identifying live hosts

Malicious Flash Analysis Engine

This kind of alert indicates that a malicious file transfer is detected by Flash Analysis Engine.

Malware Being Redownloaded

This kind of alert indicates that an action to redownload a known malware that has been blocked.

Multi-Attack Correlation

It refers to the categories of attacks which use Multiple Attack Correlation mechanism. Multi-AID attacks can correlate attacks to identify zero-day, DoS, and Bot behavior.

Multi-Attack Known Bot

Multiple attack correlation used for known Bots

Multi-Attack Heuristic Bot

Multiple attack correlation used for zero day attack detection

Non-standard Port

Any traffic activities suggesting that a standard protocol running over non-standard ports according to specifications.

Trellix IPS Analysis

This kind of alert indicates that a malicious file transfer is detected by Trellix Advanced Malware engine.

Over Threshold

Any of the well-defined traffic thresholds has been crossed. Examples include ICMP packet rate, IP fragment rate, and so forth.

PDF Emulation

This kind of alert indicates that a malicious file transfer is detected by JavaScript Emulation engine.

Phishing

It is an email-fraud method in which the perpetrators send out legitimate looking email in attempt to gather personal and financial information from recipients. Typically, the messages appear to come from well-known and trustworthy websites. Websites that are frequently spoofed by phishers include oBey, MSG, Yahoo, etc.

"Phishing" is a form of Internet fraud that aims to steal valuable information, such as credit cards, social security numbers, user IDs, and passwords. A fake website is created that is similar to that of a legitimate organization, typically a financial institution such as a bank or insurance company. An email is sent requesting that the recipient access the fake website (which is usually a replica of a trusted site) and enter their personal details, including security access codes.

Port Scan

Well-defined sequence of packets sweeping through a range of destination ports on a given IP, typically aiming at identifying open ports on the target host.

Privileged Access

Privileged access indicates the most serious type of successful exploitation, where unauthorized access to privileged accounts has been obtained. For example, a successful buffer overflow on a Unix server may open a root shell for the attacker. Alternatively, the attacker may have achieved successful permission elevation from a legitimate user account, or from a remote access compromise. Privileged access allows the attacker to potentially take complete control of the compromised system.

Probe

Probes of specific service or host, typically based on specially constructed packets, for example unusual flag settings

Protocol Violation

Unusual application protocol behaviors, including invalid field values or invalid command sequences, and so forth

Potentially Unwanted Program

A Potentially Unwanted Program (PUP) is a program that may be unwanted, despite the possibility that users consented to download it. PUBs include spyware, adhere, and dialers, and are often downloaded in conjunction with a program that the user wants. Trellix differentiates PUPs from other types of malware, such as viruses, Trojans, and worms, which can be safely assumed to be unwanted by the user.

Read Exposure

With a successful attack, this suggests that a breach of confidentiality has occurred. Examples include directory traversal, dump of file content such as CGI script, or read of other sensitive data files such as password and database records.

Remote Access

Remote access indicates a potentially successful exploitation in which unauthorized access has been obtained. For example, a successful buffer overflow on a Windows server may open a Windows command shell for the attacker. The remote access does not have to be for a privileged user to begin with, but an attacker may be able to perform further attacks to achieve permission elevation once remote access is obtained.

Restricted Access

Any activities related to using any network resources that are explicitly forbidden, for example, emails to/from particular addresses and browsing of specific URLs.

Restricted Application

Any activities related to running network applications that are forbidden by policy. Examples include running an IRC or music share server on the corporate network without authorization.

Sensitive Content

Any content keyword matches that are deemed to indicate transmission of sensitive information, for example, document with "Company Confidential" marking.

Service Sweep

An alert indicates that a client scans for services on your network or sub network, thus leading to increased bandwidth corruption and increase in network traffic. It is usually generated by a P2P client. A Service Sweep is an attempt to determine if a service is running on a range of machines. The hacker will pick one port (usually 25-SMTP, 80-HTTP, or 139-NetBIOS SSN) and a range of IP addresses.

A Ping Sweep is an attempt to see which machines in a network are on and responding.

The easiest way to detect these in a trace is to look for ARP packets. So, create a filter looking for ARP requests.

Shellcode Execution

This kind of alert indicates the most severe form of buffer overflow attacks, that is, a buffer overflow attack carrying shellcode payload. Shellcode is a general term used for a piece of executable code that, upon successful execution on the target system, modifies the target's configuration or behavior for malicious purposes.

Statistical Deviation

Indicates that a significant change was detected in the packet rate for a particular traffic measure. For example, if in your normal flow of traffic, TCP SYN packets make up between 23–28% of the traffic, a short-term measure of TCP SYN traffic at 40% may indicate a DoS attack.

TIE File Reputation

This kind of alert indicates that a malicious file transfer is detected by Trellix Threat Intelligence Exchange (TIE), which takes advantage of Trellix Data Exchange Layer to consolidate threat information, including malware confidence, infection timelines, and prevalence. TIE data sources include Global Threat Intelligence (GTI), Trellix Intelligent Sandbox, and ePolicy Orchestrator (ePO).

Trojan

Refers to a malicious program that works in the background and perform malicious actions. For example, the Trojan could allow full access of the affected system to the creator. Trojans are usually packaged in innocuous file downloads or links.

Unassigned

This category is for attacks that fall outside the scope of the known subcategories in the Trellix IPS environment. For example, if an attacker comes along a Van Eck device and starts conducting Tempest attacks, "unassigned" would be the description.

Unauthorized IP

Any traffic activities suggesting existence of IP addresses that are not known to be authorized for the protected network.

Virus

Any network event or payload specifically related to a virus. Virus can inflict many different types of damage to its target, ranging from stealing or destroying information to installing backdoor processes. However, a virus relies on other carriers, for example, email, to propagate through the network.

Worm

Any network event or payload specifically related to worm activities. A worm can inflict many different types of damages to its target, ranging from stealing or destroying information to installing backdoor processes. The worm differs from a virus in that it can propagate itself through the network.

Write Exposure

With a successful attack, this suggests that a breach of integrity and/or authenticity of data has occurred. Examples include creation/removal of files and modification of files for system configuration or user passwords. With write exposures, there is often more severe indirect impact, for example, breach of access control by adding an illegal user account records.