The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Audience

Prev Next

Custom Attack Editor is designed for sophisticated users with expertise in networking and intrusion prevention. The ability to create a custom attack is a double-edged sword. It can be a very powerful detection and defense mechanism, but at the same time, when used without training and experience, a custom attack can cause harm to your network and the business that depends on it. In addition, without a significant amount of experience in both using and configuring detection mechanisms for network intrusion detection devices, it is possible to make mistakes that can render your detection device essentially useless. For example, a mistake in implementation of a signature on a high-traffic network could cause such a large number of alerts to be generated that it would render the Manager unusable. On the opposite end of the spectrum, without proper experience and expertise, it is likely that a user might create a signature that would never detect security incidents (due to errors in tests or detection window, for example), despite the fact that the signature might be intended to detect very important events specific to your network.

Since a poorly written custom attack can cause many more problems than it solves, Trellix recommends that an attack writer possesses the following knowledge:

  • A strong understanding of computer networking

  • Experience with networks running the protocol for which you intend to create a custom attack, including a good packet-level understanding of the protocol

  • The ability to recognize the difference between "good" and "bad" traffic. That is, traffic that is correct and valid for your network and the devices that comprise it, and traffic that is anomalous to your network's configuration and security policies.

  • A strong understanding of Snort rules language, if you plan to use Snort Custom Attacks

While the fact that Trellix IPS provides deep parsing of application protocols and supports complex attack-definition structures may seem overwhelming to first-time users, it is reasonably straightforward to create custom attacks after crossing this initial hurdle.