The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages expected in early November 2026. We hope you enjoy the updated experience.

Attack tab

Prev Next

The Attack tab enables you to name your attack and type a description.

Option Definition
State Select the state of the custom attack. The choices are Published and Staged.
Name The name you assign to the attack. "UDS" is automatically prefixed before every created attack name. For example, if you name the new attack "HTTP Attack XYZ", it appears as "UDS-HTTP Attack XYZ" in the Custom Attack Editor, as well as in the attack database when you subsequently save the attack in the Manager server.
Description Use this area for notes and other pertinent information.

Tip

We recommend that you enter useful information in the Description field for easy future reference.

Severity Select a severity from the drop-down list. Choices are as follows:
  • High (most severe): High severity is divided into three categories — High 9, High 8, and High 7.
  • Medium: Medium severity is divided into three categories — Medium 6, Medium 5, Medium 4.
  • Low (least severe): Low severity is divided into three categories — Low 3, Low 2, and Low 1.
Protection Category You must choose a Protection Category from the available options. The Protection Category indicates the intent of the attack and the intended target. For example, you can choose Client Protection/Operating Systems for an attack targeting vulnerabilities in client operating systems. In this example, Client Protection is the category and Operating Systems is a subcategory. The list of Protection Categories is pre-defined and provided by Trellix Labs. You cannot modify it. This list is updated when you update the Signature Set.
Detection Type Select the type of detection from the options that relisted.
Attack Target Select the appropriate attack target.
Blocking Select the appropriate blocking. You can either block only the attack packet or the entire flow.
Non-editable Fields
Benign Trigger Probability This is an indication of the probability that the Snort Custom Attack will alert on traffic that may not be an attack. The default value is Medium, which you cannot modify.
Attack Category This column indicates the type of attack.
Trellix IPS ID The numeric ID assigned for the attack by the Manager for database archival. The Manager assigns the ID after you save it in the Manager server. For Snort Custom Attacks, the IDs begin with 0xe. For Snort Custom Attacks created in the Central Manager, the IDs begin with 0xee.
Supported Device Types You can apply a Custom Attack signature for just the available device types. The value for this field depends on what you select for the corresponding rule. You cannot edit this field at the attack level, but the Manager modifies it accordingly when you change it for the corresponding rule.

Note

If you upgrade your Manager version to 9.2, those custom attacks that were configured to M-series, NS-series, and Virtual IPS Sensors get configured to Any option after the upgrade.

Last Updated Displays the time at which the signature was last updated