You can use the predefined template to create a Trellix IPS custom attack to detect an email attachment by the file name.
Steps:
Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.
The Custom Attack Editor opens with the existing Custom Attacks listed on the Native Trellix IPS Format tab.
Click
.The New Custom Attack interface opens.
In the Name field, type a new name for your attack. UDS (User-Defined Signature) is appended at the front automatically when you save the attack. For example, if you name the new attack "HTTP Attack XYZ", it appears as "UDS-HTTP Attack XYZ" in the Custom Attack Editor as well as in the attack database when you save the attack.
Note
The Trellix IPS ID is provided by the Manager when you save it in the Manager server.
Type a Description for your attack.
This area can be used for your notes or other specific information pertinent to your new attack.
Select a severity for your attack by toggling the drop-down list. Choices are High (9, 8, 7), Medium (6, 5, 4), Low (3, 2, 1), and Informational (0).
Severity is set to Medium (5) by default.
Select the most appropriate Protection Category for the attack.
Select E-mail Attachment from the Detection Type drop-down menu for the attack.
Select the required parameter for Attachment File Name and enter the corresponding value in the text box.
Custom attack to detect an email attachment by its file name.png)
Click Add.
Double-click on the attack that you created on the Native Trellix IPS Format tab.
In the Matching Criteria section, the protocol is automatically selected as SMTP.
To edit these values, select the signature on the Signature-<signature name> tab. You can modify the default values. You can also add more conditions to the signature.
Details of the Trellix IPS custom attack.png)
Click Save in the Custom Attack interface.
Until you save the attack in the database, value for the Trellix IPS ID column is not generated. The Sensor detects this attack after you deploy pending changes to the corresponding Sensor (Devices → <Admin Domain Name> → Global → Device Manager. Select the Sensors tab. Then, select the required Sensor from list and click Sync).