The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Create the signature

Prev Next

After you create the attack definition, you create the signature for the attack.

Steps:

  1. Click Signature-<signature name> tab.

  2. (Optional) Clear the Name and type a new name for your signature.

  3. For this example, you can leave the Benign Trigger Probability (BTP) and Target Host Architecture with the default values.

  4. This example is to search for a string in the HTTP URI. So, select Request Packets as the Detection Window.

  5. Based on the Sensor model that you plan to use for this example, select the Supported Device Types.

    New Signature window
    New Signature window


  6. Add the condition to the signature.

    It is in the conditions that you specify the following details:

    • The string that the Sensor should look for

    • Which section of the HTTP request should it look for the string

  7. Proceed to add the condition.