The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configuration of attack compilation

Prev Next

The Attack Compilation page enables you to specify the type of attack definitions to be included in the IPS Policies for a specific Sensor.

To access the Attack Compilation page, go to Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Attack Compilation.

The Attack Compilation page opens.

GUID-C1859030-B55D-4476-9A64-670A4FB485A2-low.png

You can select the following types of attack definitions for the Sensor:

  • Signature Set Attacks - These are the attacks from Trellixsignature set.

    When the Signature Set Attacks option is selected, the Manager allows you to choose Signature Set Attack Priorities for the Sensor. This allows the Manager to dynamically compile only critical attacks from the standard signature set for Sensors that do not have enough resources to support all attacks.

    The signature set attack priorities available are as follows:

    • All: Includes all attack definitions in the signature set. This is the default signature set attack priority selected for NS-series and Virtual IPS Sensors and provides complete attack coverage.

    • High and Medium only: It comprises of high and medium priority attacks in the signature set.

    • High only: It comprises of high priority signature set attacks. You can use this option to optimize Sensor resources on Sensor models running older Sensor software versions to support the latest signatures against most critical attacks.

      Warning

      The High Only signature set attack priority provides an attack coverage only against the most critical attacks.

  • Custom Attacks – Trellix Format — These are the Trellix Custom Attacks that are defined or received from Trellix.

  • Custom Attacks–Imported Snort Rules — These are the Snort Custom Attacks that are imported or created in the Manager.