The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Custom attack with a pattern-match signature

Prev Next

Scenario

This is about creating a Custom Attack Definition that uses pattern matching to detect any HTTP GET requests in the URI patch for a specific CGI script. This scenario is useful because it illustrates the simplest method of configuring a custom attack definition with proper syntax, defined options, and case sensitivity.

Creation of such an attack definition is also a good example of activity that may not be a malicious attack; rather, you could create such an instance and use it to track requests for sensitive information.

In order to write a proper Native Trellix IPS Format Custom Attack or a Snort Custom Attack for this example, you must identify several key elements:

  • Application protocol: HTTP

  • Where to look: URI path

  • Detection window: request

  • Request method: get

  • String to match: cgi.bin/trillion.pl or cgi.bin/trilliant.pl, where only "pl" is case insensitive

When you have all of the required elements to properly identify the activity, attack definition can be successful.

To create a custom attack definition:

  • Open the Custom Attack Editor.

    Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.