In Trellix IPS, attack definitions are a mechanism used to identify and protect against malicious actions taken against your network. An attack definition is the aggregation of the signatures (or rule) and other supporting data that can identify a specific network event. When you select an attack, you are essentially selecting a group of conditions defined in a rule or signature(s).
Note
A rule in a Snort Custom Attack corresponds to the signatures in a Trellix IPS Custom Attack.
Policies are applied to the Sensor and consist of one or more attacks. Traffic passing through the Sensor is compared to the attacks enabled in the policies, and if any traffic is identified as malicious by an attack definition, an alert is triggered to notify you of the incident.