The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create New Attack Set Profile at Domain Level

Prev Next

This URL creates new attack set profile at domain level.

Resource URL

POST /domain/<domainId>/attacksetprofile/createruleset

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domainId

Domain id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

Mandatory

policyName

Policy name

String

Yes

description

Policy description

String

Yes

enableRfSBExpoit

RfSB exploit configuration

Boolean

Yes

enableRfSBMalware

RfSB malware configuration

Boolean

Yes

enableRfSBRecon

RfSB recon configuration

Boolean

Yes

enableRfSBPolicy

RfSB policy configuration

Boolean

Yes

isEditable

Attack set editable configuration

Boolean

No

action

Inclusion/exclusion of rules Values can be:

  • INCLUDE

  • EXCLUDE

String

No

comment

Comments

String

No

isSpecificAttack

Specific attack name

Boolean

No

AttackList

List of attacks

String

No

minSeverity

Severity level values can be:

  • NONE

  • HIGH_1

  • HIGH_8

  • HIGH_7

  • MEDIUM_6

  • MEDIUM_5

  • MEDIUM_4

  • LOW_3

  • LOW_2

  • LOW_1

  • INFORMATIONAL_0

String

No

maxBTP

BTP level values can be:

  • NONE_0

  • HIGH_7

  • HIGH_6

  • MEDIUM_5

  • MEDIUM_4

  • MEDIUM_3

  • LOW_2

  • LOW_1

String

No

attackType

Type of attack values can be:

  • ANY

  • RF_SB_ONLY

String

No

attackCategory

Attack category

String

No

application

Application list

String

No

Protocol

Protocols

String

No

operatingsystem

Operating system

String

No

Response Parameters

Following fields are returned.

Field Name

Description

Data Type

createdResourceId

Unique id of the created policy

Number

Example

Request

POST https://<NSM_IP>/sdkapi/domain/<domainId>/attacksetprofile/createruleset

{
"policyName": "New Attackset_API",
"description": "Test creation ",
"enableRfSBExpoit": false,
"enableRfSBMalware": false,
"enableRfSBRecon": false,
"enableRfSBPolicy": false,
"rules": [
  {
"action": "INCLUDE",
"comment": null,
"isSpecificAttack": false,
"AttackList": [],
"minSeverity": "LOW(2)",
"maxBTP": "MEDIUM(4)",
"attackType": "ANY",
"attackCategory": [
  null
],
"application": [
  null
],
"protocol": [
  null
],
"operatingsystem": [
  null
],
},
  {
"action": "EXCLUDE",
"comment": null,
"isSpecificAttack": false,
"AttackList": [],
"minSeverity": null,
"maxBTP": null,
"attackType": "ANY",
"attackCategory": [
  "Reconnaissance"
],
"application": [
  null
],
"protocol": [
  null
],
"operatingsystem": [
  null
],
}
],
}

Response

{
createdResourceId :1
}

Error Information

Following error codes are returned by this URL:

No

SDK API errorId

SDK API errorMessage

1

1105

Invalid domain

2

7001

Invalid policy id

3

7001

Duplicate name detected

4

7001

The first rule in the list must be an Include rule

5

7001

Invalid attack type input

6

7001

A rule cannot contain multiple items of multiple categories at the same time