You can use the pre-defined template to create a Trellix IPS custom attack to detect a URL.
Steps:
Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.
The Custom Attack Editor opens with the existing Custom Attacks listed on the Native Trellix IPS Format tab.
Click
.The New Custom Attack interface opens.
In the Name field, type a new name for your attack. UDS (User-Defined Signature) is appended at the front automatically when you save the attack. For example, if you name the new attack "HTTP Attack XYZ", it appears as "UDS-HTTP Attack XYZ" in the Custom Attack Editor as well as in the attack database when you save the attack.
Note
The Trellix IPS ID is provided by the Manager when you save it in the Manager server.
Type a Description for your attack.
This area can be used for your notes or other specific information pertinent to your new attack.
Select a severity for your attack by toggling the drop-down list. Choices are High (9, 8, 7), Medium (6, 5, 4), Low (3, 2, 1), and Informational (0).
Severity is set to Medium (5) by default.
Select the most appropriate Protection Category for the attack.
Select URL from the Detection Type drop-down menu for the attack.
Enter the URL that is to be detected, then click Add.
If you are specifying the protocol, you can specify only HTTP or HTTPS in the URL. The attack is listed on the Native Trellix IPS Format tab.
Create a Trellix IPS custom attack to detect a URL.png)
Double-click on the attack that you created on the Native Trellix IPS Format tab.
In the Matching Criteria section, the protocol is automatically selected as HTTP.
You can also add more conditions to the signature. From the Add Custom Attack window, you can also add more signatures to the attack.
Details of the Trellix IPS custom attack.png)
Click Save in the Custom Attack interface.
Until you save the attack in the database, value for the Trellix IPS ID column is not generated. The Sensor detects this attack after you deploy pending changes to the corresponding Sensor (Devices → <Admin Domain Name> → Global → Device Manager. Select the Sensors tab. Then, select the required Sensor from the list and click Sync).