The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Automated blocking of attacks: Exceptions

Prev Next

While this feature helps automating the process of blocking of specific attacks in your network environment, the underlying mechanism has been carefully designed to avoid blocking of false-positives which may result in network disruptions. Some of the exceptions to these rules for blocking include the following:

  • There are certain attacks which should never be blocked the user, irrespective of their network infrastructure and requirements. Blocking these attacks can cause anomaly and unexpected network outages. Trellix Advanced Research Center provides guidelines on the attack IDs and criteria defining the attacks which should not be blocked. The blocking mechanisms in the Attack Set Profiles page as well as IPS page of the Manager are built following these guidelines so as to prevent the accidental blocking of such attacks.

  • Rules created for automatic blocking of attacks are not applicable to Informational and Low severity attacks.

  • Rules created on the Attacks to Block tab during attack set profile configuration do not control the automatic blocking of DoS threshold, DoS learning and Correlation-based Reconnaissance attacks.

  • The default or preconfigured attack set profiles are read-only. So, these rules for blocking can be created for custom attack set profiles only.