The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a snort custom attack — an example

Prev Next

To write a Snort Custom Attack definition for the scenario explained in the previous section:

Steps:

  1. In the Custom Attack Editor, click Snort Format tab.

  2. Click GUID-F3F18CF8-B95D-4C8C-8DB8-996CDB6087FB-low.png.

    The New Snort Rule text box opens.

  3. Select one of the options from the State drop-down menu.

  4. Construct the Snort rule for the scenario, which is the following:

    alert tcp any any -> 192.168.1.1 80 (msg:"CGI: Trillion or Trilliant";content:"cgi.bin\trilli";http_uri;pcre:"/cgi.bin\trilli(on|ant).[Pp][Ll]/";priority:2;sid:2051;rev:1;)

    Add Snort Rule window
    Add Snort Rule window


    Some points to note regarding the rule:

    • Specifying the destination IP address improves the performance of the Sensor.

    • As you are adding the Snort rule directly in the Custom Attack Editor, as a best practice, you need to specify the destination port number. The Sensor then checks only the HTTP request packet for this rule.

    • You need to specify the msg, priority, SID, and the revision number.

  5. Select Check for Overlap with Trellix IPS Attacks to verify if the rule matches an existing Trellix IPS attack definition.

  6. Select Advanced Protection Options/Web Application Server Protection as the Protection Category.

  7. Click Add.

    The Attack window opens.

    Edit Snort Attack window
    Edit Snort Attack window


  8. Note that the Manager assigns the Attack Name based on the msg option and SID of the rule.

  9. Set the severity to Medium. This is because the priority of the rule is 2.

  10. Note that the Protocol is set to http. This is because the destination port number is 80.

  11. Note that the Benign Trigger Probability is set to the default value.

  12. Close the Attack window.

  13. In the Custom Attacks window, click Save to save the Snort Custom Attack in the Manager server database.

  14. Make sure the Snort Custom Attack is saved in the database and also published in the policies.