The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Compile the attack definitions

Prev Next

In the policies, you can use the attack definitions from the following types:

  • Trellix IPS-supplied Attack definitions (signature set)

  • Trellix IPS Custom Attack

  • Snort Custom Attack

There can be instances where you may want to publish only specific types of attack definitions for a specific Sensor. For example, you may want to configure a Sensor to monitor traffic for specific attacks. You can also use this feature to troubleshoot and isolate the attack definitions that may cause an adverse effect on a Sensor's performance.

Steps to specify the attack definition type for a Sensor:

  1. Select Devices → <Admin domain> → Devices → <Device Name> → Setup → Attack Compilation.

  2. Select the attack definition type:

    • Signature Set Attacks - These are the attacks from Trellix IPS signature set.

      When the Signature Set Attacks option is selected, the Manager allows you to choose Signature Set Attack Priorities for the Sensor. This allows the Manager to dynamically compile only critical attacks from the standard signature set for Sensors that do not have enough resources to support all attacks.

      The signature set attack priorities available are as follows:

      • All: Includes all attack definitions in the signature set. This is the default signature set attack priority selected for NS-series and Virtual IPS Sensors and provides complete attack coverage.

      • High and Medium only: It comprises of high and medium priority attacks in the signature set. This option provides partial attack coverage.

      • High only: It comprises of high priority signature set attacks. You can use this option to optimize Sensor resources on Sensor models running older Sensor software versions to support the latest signatures against most critical attacks.

        Warning

        The High Only signature set attack priority provides an attack coverage only against the most critical attacks.

    • Custom Attacks - Trellix IPS Format: Select this if you want to use the definitions that you created in the Trellix IPS format. This also includes the Trellix IPS-supplied custom attacks (emergency UDS).

    • Custom Attacks-Imported Snort Rules: Select this if you want to use the Snort Custom Attack definitions that you created or imported.

  3. Click Save.

    When you update a Sensor with the configuration changes, only the attack definitions from the type specified here are pushed to the Sensor.

    GUID-C1859030-B55D-4476-9A64-670A4FB485A2-low.png