After you create the attack definition, you create the signature for the attack.
Steps:
In the New Custom Attack window, click Signature-<signature name> tab.
New Signature window.png)
(Optional) Clear the Name and type a new name for your signature.
For this example, you can leave the Benign Trigger Probability (BTP), Target Host Architecture, and Detection Window with the default values.
Based on the Sensor model that you plan to use for this example, select the Supported Device Types.
Add the condition to the signature.
It is in the conditions that you specify the following details:
The string that the Sensor should look for.
Which section of the http request should it look for the string.
Proceed to add the condition.