The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Attack tab

Prev Next

The Attack tab enables you to name your attack and type a description.

Option

Definition

State

Select the state of the custom attack. The choices are Published and Staged.

Name

The name you assign to the attack. "UDS" is automatically prefixed before every created attack name. For example, if you name the new attack "HTTP Attack XYZ", it appears as "UDS-HTTP Attack XYZ" in the Custom Attack Editor, as well as in the attack database when you subsequently save the attack in the Manager server.

Description

Use this area for notes and other pertinent information.

Tip

We recommend that you enter useful information in the Description field for easy future reference.

Severity

Select a severity from the drop-down list. Choices are as follows:

  • High (most severe): High severity is divided into three categories — High 9, High 8, and High 7.

  • Medium: Medium severity is divided into three categories — Medium 6, Medium 5, Medium 4.

  • Low (least severe): Low severity is divided into three categories — Low 3, Low 2, and Low 1.

Protection Category

You must choose a Protection Category from the available options. The Protection Category indicates the intent of the attack and the intended target. For example, you can choose Client Protection/Operating Systems for an attack targeting vulnerabilities in client operating systems. In this example, Client Protection is the category and Operating Systems is a subcategory. The list of Protection Categories is pre-defined and provided by Trellix Advanced Research Center. You cannot modify it. This list is updated when you update the Signature Set.

Detection Type

Select the type of detection from the options that relisted.

Attack Target

Select the appropriate attack target.

Blocking

Select the appropriate blocking. You can either block only the attack packet or the entire flow.

Non-editable Fields

Benign Trigger Probability

This is an indication of the probability that the Snort Custom Attack will alert on traffic that may not be an attack. The default value is Medium, which you cannot modify.

Attack Category

This column indicates the type of attack.

Trellix IPS ID

The numeric ID assigned for the attack by the Manager for database archival. The Manager assigns the ID after you save it in the Manager server. For Snort Custom Attacks, the IDs begin with 0xe. For Snort Custom Attacks created in the Central Manager, the IDs begin with 0xee.

Supported Device Types

You can apply a Custom Attack signature for just the available device types. The value for this field depends on what you select for the corresponding rule. You cannot edit this field at the attack level, but the Manager modifies it accordingly when you change it for the corresponding rule.

Last Updated

Displays the time at which the signature was last updated