The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a packet search protocol instance

Prev Next

Several packet search protocol instances are provided with Trellix IPS. You can create a packet search protocol instance. These applications use protocols that are neither defined by an RFC nor by any Trellix-defined protocol specification.

Steps:

  1. In the Custom Attack Editor, select Other Actions → Manage Grepping Protocols.

    The Manage Grepping Protocols dialog box opens.

  2. Go to Custom tab.

  3. Type a name. This name is listed in the "Select Protocol" step during signature creation.

    Type a verbose name. This name is for reference purposes.

  4. Select the transport protocol as either TCP or UDP.

  5. Type a port number in the Ports field, then click Add. Repeat for multiple port numbers.

    Note

    You cannot add a port number that is already used by a defined protocol, such as 21 (FTP) or 80 (HTTP). Also, if you create a packet grep instance for port 888, you cannot create another packet grep instance for that port.

    GUID-6668B121-42C7-42BC-9555-177D52C258FD-low.png
  6. Click Save when finished.

  7. Create a new signature instance that utilizes your created packet grep instance.