After you create the attack definition, you create the signature for the attack.
Task
-
In the
New Custom Attack window, click
Signature-<signature name> tab.
New Signature window 
- (Optional) Clear the Name and type a new name for your signature.
- For this example, you can leave the Benign Trigger Probability (BTP), Target Host Architecture, and Detection Window with the default values.
- Based on the Sensor model that you plan to use for this example, select the Supported Device Types.
-
Add the condition to the signature.
It is in the conditions that you specify the following details:
- The string that the Sensor should look for
- Which section of the HTTP request should it look for the string
- Proceed to add the condition.