The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a Trellix IPS custom attack to detect a string in an application running over a custom port

Prev Next

You can use the predefined template to create a Trellix IPS custom attack to detect a string in an application that is running over a custom port.

Steps:

  1. Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.

    The Custom Attack Editor opens with the existing Custom Attacks listed on the Native Trellix IPS Format tab.

  2. Click GUID-F3F18CF8-B95D-4C8C-8DB8-996CDB6087FB-low.png.

    The New Custom Attack interface opens.

  3. In the Name field, type a new name for your attack. UDS (User-Defined Signature) is appended at the front automatically when you save the attack. For example, if you name the new attack "HTTP Attack XYZ", it appears as "UDS-HTTP Attack XYZ" in the Custom Attack Editor as well as in the attack database when you save the attack.

    Note

    The Trellix IPS ID is provided by the Manager when you save it in the Manager server.

  4. Type a Description for your attack.

    This area can be used for your notes or other specific information pertinent to your new attack.

  5. Select a severity for your attack by toggling the drop-down list. Choices are High (9, 8, 7), Medium (6, 5, 4), Low (3, 2, 1), and Informational (0).

    Severity is set to Medium (5) by default.

  6. Select the most appropriate Protection Category for the attack.

  7. Select Text in Custom Application from the Detection Type drop-down menu for the attack.

  8. Select the appropriate Grepping Protocol.

  9. Enter the string that you want the Sensor to detect in the Text to Match field and click Add.

    The Text to Match field is case-sensitive. That is, the Sensor matches the case when it detects the string.

    Custom attack to detect a string in an application on a custom port
    Custom attack to detect a string in an application on a custom port


  10. Double-click on the attack that you created on the Native Trellix IPS Format tab.

    You can modify the values of the signature on the Signature-<signature name> tab. You can also add more conditions to the signature.

  11. Click Save in the Custom Attack interface.

    Until you save the attack in the database, value for the Trellix IPS ID is not generated. The Sensor detects this attack after you deploy pending changes to the corresponding Sensor (Devices → <Admin Domain Name> → Global → Device Manager. Select the Sensors tab. Then, select the required Sensor from list and click Sync).