The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create an attack definition for packet grep protocol match

Prev Next

This scenario is about creating a Custom Attack Definition that uses packet grep protocol match to detect if the DNP3 protocol contains a specific character sequence.

In order to write a proper Native Trellix IPS Format Custom Attack for this example, you must identify several key elements:

  • Application protocol: dnp3

  • Packets to parse: Request Packets Only

  • Text to match: \x00\x00\x00\x3a\x20\x45\x56\x00\x0a

Steps to create the attack definition for this example:

  1. In the Custom Attack Editor, click GUID-F3F18CF8-B95D-4C8C-8DB8-996CDB6087FB-low.png.

    The New Custom Attack interface opens.

    GUID-3EB7CCB4-A36F-41F8-BB0D-1EC2405A7B00-low.png
  2. Select one of the options from the State drop-down menu.

  3. You can specify a name such as "Custom Exploit: Packet Grep Protocol Match" as the Name.

    The letters "UDS" (user-defined signature) are appended to the front of the name upon completion; thus, this attack appears as "UDS-Custom Exploit: Packet Grep Protocol Match" in the Custom Attack Editor, as well as the attack database when you save in the Manager server.

  4. Type a description for your attack. This area can be used for your notes or other specific information pertinent to your new attack.

  5. You can select Medium (5) as the Severity because this example scenario does not necessarily involve malicious activity.

  6. Select Advanced Protection Options/Web Application Server as the Protection Category.

  7. Select Custom Exploit (Signature Based) from the Detection Type drop-down menu for the attack.

  8. Click Next.

    GUID-0B2936AA-6016-4E2A-AF52-5FB77B970543-low.png
  9. Select Client or Server as Attack Target.

  10. Select Attack Packet Only as Blocking (As Applicable).

  11. In the Matching Criteria section, select Protocol as the Criterion and select pktsearch as the protocol.

    GUID-D886D376-714A-4375-B5D3-FE895A8C90EA-low.png
  12. Attack details configuration is complete. Continue to create signature.