The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create snort custom attacks

Prev Next

The following is the high-level approach for creating Snort Custom Attacks.

Steps:

  1. Have a clear understanding on what you are trying to achieve through these attacks. See if there are any alternatives or better methods to achieve the same. Identify the related protocols, applications, hardware and software platforms for the attack. Make sure you have all the required information in hand.

  2. Understand the mechanics of a Snort Custom Attack. You need to have a strong understanding of network concepts as well as Snort rules language to create effective Snort Custom Attacks.

  3. Take a quick tour of the Custom Attack Editor. Get familiar with the Custom Attack Editor - the tool that you will use to manage Custom Attacks. Understand the interfaces related to Snort Custom Attacks.

  4. Verify the required variables. Check if the variables that you plan to use are available in the Sensor.

  5. Create Snort Custom Attacks. There are two methods:

    • You can import the rules from a file.

    • You can construct the Snort rules directly in the Custom Attack Editor.

  6. Check the rules that failed to convert. The Sensor automatically converts all the valid rules, which you imported or wrote, to Trellix IPS's proprietary format. Note that some rules could have failed to convert. Troubleshoot and fix the rules that failed to convert.

    Note

    If you are creating or importing Suricata Snort rules, ensure that one of TCP, UDP, IP, and ICMP protocols is used in the Snort rules.

  7. Save the converted rules in the Manager database.

  8. Once saved in the database, the rules are like any other custom attack definition. For example, you may want to customize the response action for the saved Snort rules, or you may want to delete a Snort rule from the database.

  9. Update the respective Sensors with the changes.

    The Sensors raise alerts based on the saved Snort rules. You can view these alerts in the Attack Log.