The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create a Trellix IPS custom attack to detect TCP connection attempts

Prev Next

You can use the predefined template to create a Trellix IPS custom attack to detect TCP connection attempts from specific IP addresses.

Steps:

  1. Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.

    The Custom Attack Editor opens with the existing Custom Attacks listed on the Native Trellix IPS Format tab.

  2. Click GUID-F3F18CF8-B95D-4C8C-8DB8-996CDB6087FB-low.png.

    The New Custom Attack interface opens.

  3. In the Name field, type a new name for your attack. UDS (User-Defined Signature) is appended at the front automatically when you save the attack. For example, if you name the new attack "HTTP Attack XYZ", it appears as "UDS-HTTP Attack XYZ" in the Custom Attack Editor as well as in the attack database when you save the attack.

    Note

    The Trellix IPS ID is provided by the Manager when you save it in the Manager server.

  4. Type a Description for your attack.

    This area can be used for your notes or other specific information pertinent to your new attack.

  5. Select a severity for your attack by toggling the drop-down list. Choices are High (9, 8, 7), Medium (6, 5, 4), Low (3, 2, 1), and Informational (0).

    Severity is set to Medium (5) by default.

  6. Select the most appropriate Protection Category for the attack.

  7. Select Connection from Specific IP from the Detection Type drop-down menu for the attack.

  8. Enter the IPv4 or IPv6 Source IP Address from which TCP connection attempts are to be detected and click Add.

    The attack is listed on the Native Trellix IPS Format tab.

    GUID-F9B3C546-E7A0-4D9F-AC66-0A6DB72E5995-low.png
  9. Double-click on the attack that you created on the Native Trellix IPS Format tab.

    In the Matching Criteria section, the Software Package (OS) is selected as tcpip-machine.

    GUID-B75E6978-25B6-4E3D-9B91-5CEF09AFF2C3-low.png

    You can modify the values of the signature on the Signature-<signature name> tab. You can also add more conditions to the signature. For example, do the following to add conditions based on TCP flags:

    1. Add a signature or edit a signature.

    2. In the corresponding signature, click GUID-F3F18CF8-B95D-4C8C-8DB8-996CDB6087FB-low.png.

    3. Add a condition by clicking GUID-621EB179-B0A5-43D9-99A3-64CB0BB6FB20-low.png or GUID-B4864D1C-95C3-4825-96BA-EAE9E98FDAC8-low.png.

    4. From Comparison Type list, select Single Fixed Field Match.

    5. Select tcp from the Protocol drop-down menu.

    6. Select the required flag from the Protocol Field.

    7. Select the Operator.

    8. Enter the value to match in the Integer or IP to Match field.

    9. Select Ignore Bitmask if you want to ignore the bitmask.

    10. Click Save.

  10. Click Save in the Custom Attack interface.

    Until you save the attack in the database, value for the Trellix IPS ID column is not generated. The Sensor detects this attack after you deploy pending changes to the corresponding Sensor (Devices → <Admin Domain Name> → Global → Device Manager. Select the Sensors tab. Then, select the required Sensor from list and click Sync).