The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Best methods for rule set creation

Prev Next

There are two best practice methods employed for creating rule sets.

  • General-to-specific rule creation — The first method is general-to-specific. Start with an include rule that covers a broad range of operating systems, applications and protocols. After this, create one or more exclude rules to strip away specific operating systems or protocols, thus focusing the rule set on the environment where it will be enforced. For example, start with an include rule for all Exploit category attacks. Follow this with multiple exclusion rules that strip away protocols, applications, severities, etc., that are rarely or never seen in a zone of your network.

  • Collaborative rule creation — The second method is collaboration - Create multiple include rules within one rule set for each category, operating systems or combination that needs to be detected. Each criterion must be matched in order for an alert to be triggered. For example, create the first rule in the set with the Exploit category, Unix as the OS, Sendmail as the application, and SMTP as the protocol. Next, create another include rule for Exploit, Windows 2000, WindMail, and so forth in the same manner. Each include rule added broadens the scope of the detection.

    For more information, see How to create Ignore rules for an applied IPS policy.