The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Before you create a custom attack

Prev Next

Creating attack definitions is a complex topic on which books have been written. It is highly recommended that you refer to one of these books if you are not an experienced attack definition author. Pay close attention to detail when you define your attacks, as there are many ways to shoot yourself (and your network!) in the foot as you develop expertise with attack definitions.

Before creating a custom attack, you should carefully consider the requirement that you are trying to address. This means that you should have a clear understanding of the attack's purpose, such as a specific business or policy requirement.

You should have a clear rationale for using a custom attack instead of another mechanism. In some cases, a custom attack may not be the appropriate solution. For this reason, you should consider whether you can address your need with other technical means, such as router ACLs, firewall rules, or a network sniffer.

Finally, you should verify that the custom attack you intend to create does not duplicate any attack provided in Trellix IPS. However, in case of a duplicate, you have the flexibility to use both or just the custom attack instead of the Trellix IPS-supplied attack. If you choose to use both, note that the Sensor may raise two alerts for the same attack traffic.