The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuration of attack compilation

Prev Next

The Attack Compilation page enables you to specify the type of attack definitions to be included in the IPS Policies for a specific Sensor.

To access the Attack Compilation page, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Attack Compilation.

The Attack Compilation page opens.

You can select the following types of attack definitions for the Sensor:

  • Signature Set Attacks - These are the attacks from Trellixsignature set.

    When the Signature Set Attacks option is selected, the Manager allows you to choose Signature Set Attack Priorities for the Sensor. This allows the Manager to dynamically compile only critical attacks from the standard signature set for Sensors that do not have enough resources to support all attacks.

    The signature set attack priorities available are as follows:

    • All: Includes all attack definitions in the signature set. This is the default signature set attack priority selected for NS-series and Virtual IPS Sensors and provides complete attack coverage.

      Attention

      The Signature Set Attack Priorities option All is available only for NS-series and Virtual IPS Sensors.

      Important

      The Signature Set Attack Priorities can be configured only on Manager version 9.2.7.31 or later. For configuring the Signature Set Attack Priorities option as All, you should have NS-series Sensor software version 9.2.5.72 or later and Virtual IPS Sensor software version 9.2.7.26 or later. If you are running any NS-series Sensor software versions prior to 9.2.5.72 or Virtual IPS Sensor versions prior to 9.2.7.26, Trellix recommends you to use High and Medium only signature set attack priority that provides partial attack coverage.

    • High and Medium only: It comprises of high and medium priority attacks in the signature set. This is the default signature set attack priority selected for M-series Sensors and provides partial attack coverage.
    • High only: It comprises of high priority signature set attacks. You can use this option to optimize Sensor resources on M-series Sensors or Sensor models running older Sensor software versions to support the latest signatures against most critical attacks.

      Warning

      The High Only signature set attack priority provides an attack coverage only against the most critical attacks. To accommodate complete attack coverage using All signature set attack priority, Trellix recommends you to migrate your M-series Sensors to the latest NS-series or Virtual IPS Sensors.

  • Custom Attacks – Trellix Format — These are the Trellix Custom Attacks that are defined or received from Trellix.
  • Custom Attacks–Imported Snort Rules — These are the Snort Custom Attacks that are imported or created in the Manager.