Steps to create the attack definition for this example:
Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.
The Custom Attack Editor opens with the existing Custom Attacks listed on the Native Trellix IPS Format tab.
Click
.The New Custom Attack interface opens.
In the Name field, type a new name for your attack.
The letters "UDS" (user-defined signature) are appended to the front of the name upon completion when you save it in the Manager server.
Type a description for your attack. This area can be used for your notes or other specific information pertinent to your new attack.
Select Advanced Protection Options/Web Application Server Protection as the Protection Category.
Select URL from the Detection Type list.
Enter the URL that is to be detected, then click Add.
.png)
In the Matching Criteria section, the protocol is automatically selected as HTTP.
Select Software Package (OS) as the Criterion.
Select iis from the Software Package list .
Select windows from the Operating System list and then click Add.
Verify that both HTTP and IIS appear in the Matching Criteria table.
.png)
Click Update.
Attack details configuration is complete. Continue to create signature.