The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a signature using your new packet search protocol

Prev Next

Prerequisite:

Create a Trellix IPS Custom Attack definition and in the Matching Criteria section and select tcpip-machine as the Software Package.

Steps:

  1. Click Signature-<Signature ID> tab.

    The Signature Details section is visible.

  2. Add a comparison with at least one condition. Do the following:

    1. Click Condition 1 so that it is highlighted.

      Creating a condition
      Creating a condition


    2. Click AND.

      The Add ADD Comparision dialog box opens.

      Adding comparators
      Adding comparators


    3. Select Packet Grep Protocol Match from the Comparison Type drop-down menu.

    4. Select the protocol name that you defined from the Protocol drop-down menu.

    5. Select the signature search direction from the Parse drop-down menu. The choices are as follows:

      • Request Packets Only

      • Response Packets Only

    6. Select the regular expression matching criteria as Equals or Does NOT equal from the Operator drop-down menu.

    7. Add a pattern to match in the Text to Match text box.

    8. Optionally, click the Ignore Case check box if you want the pattern to be matched regardless of [letter] case.

    9. Optionally, click the Ignore String Position check box.

    10. Click Save after adding the condition details. Your comparison appears under Condition 1.

  3. Click Update in the attack editor window.

  4. Click Save in the Custom Attacks window.