The capability of creating more than one signature in an attack definition is part of what allows Trellix IPS to keep its false positive rate so low. You should create multiple signatures for an attack, when possible, so as to be both more inclusive and more specific. You may want to create a generic signature that will catch all attack variants (including those which are unknown to you). You should also create more specific signatures to detect particular pieces of exploit code, if possible. This can be valuable in providing pointers on what to investigate if a machine has been compromised, in addition to keeping your rate of false positives far below that of the average signature-based IPS.
Create more than one signature per attack
- Published on Oct 5, 2026
- 1 minute(s) read
Was this article helpful?