The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create an attack definition for the example

Prev Next

Steps to create the attack definition for this example:

  1. Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.

    The Custom Attack Editor opens with the existing Custom Attacks listed on the Native Trellix IPS Format tab.

  2. Click GUID-F3F18CF8-B95D-4C8C-8DB8-996CDB6087FB-low.png.

    The New Custom Attack interface opens.

  3. In the Name field, type a new name for your attack.

    The letters "UDS" (user-defined signature) are appended to the front of the name upon completion when you save it in the Manager server.

  4. Type a description for your attack. This area can be used for your notes or other specific information pertinent to your new attack.

  5. Select Advanced Protection Options/Web Application Server Protection as the Protection Category.

  6. Select URL from the Detection Type list.

  7. Enter the URL that is to be detected, then click Add.

    GUID-E999D48C-2BB4-4E0F-80A9-9FC39753F715-low.png
  8. In the Matching Criteria section, the protocol is automatically selected as HTTP.

  9. Select Software Package (OS) as the Criterion.

  10. Select iis from the Software Package list .

  11. Select windows from the Operating System list and then click Add.

  12. Verify that both HTTP and IIS appear in the Matching Criteria table.

    GUID-AAAB3CDA-EAD4-4612-AE0D-31290E5485C5-low.png
  13. Click Update.

  14. Attack details configuration is complete. Continue to create signature.