There could be unique security requirements that would not be possible to be covered in the Trellix IPS-supplied signature set. For such cases, you have the option of developing your own attack definitions. Such user-defined attacks are referred to as Custom Attack definitions or Custom Attacks.
Custom Attack Editor enables you to create Trellix IPS Custom Attacks as well as Snort Custom Attacks. Using this tool, you can also import custom attacks in bulk against defining them individually. You use the Custom Attack Editor to manage custom attacks. You can launch it from the Custom Attacks page of the Manager. From the Manager, select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.
Note
The Custom Attacks menu option is available only for the root admin domain.
The Custom Attacks page provides the following options:
Native Trellix IPS Format: You can create custom attacks in Trellix IPS's proprietary format. This type of custom attacks are signature-based. You can define one or more signatures per attack. Such attack definitions are called Native Trellix IPS Format Custom Attacks.
Snort Format: You can write rule-based custom attacks using Snort rules language, which is open-source. Such attack definitions are called Snort Custom Attacks. In case of Snort Custom Attacks, the Manager parses them to check the syntax. It then converts all valid attack definitions to Trellix IPS's format and saves them in the Manager database. Once in the database, the converted Snort rules function like any other Trellix IPS signature. So, in Trellix IPS, both signatures and rules are functionally similar implying that what applies to a signature also applies to a rule unless stated otherwise.
.png)