Trellix IPS uses a variety of methods to detect aberrant network activity. The main detection method used is attack definition. An attack defines either a rule or related signatures that specify a set of checks for capturing various attempts at exploiting a given vulnerability or creating other threat conditions.
Note
Throughout this guide, the terms attack and attack definition are used interchangeably.
Trellix IPS regularly supplies you with its own attack definitions (signature set) to protect your network. Additionally, it also provides ad hoc signature sets in case of emergencies and zero-day vulnerabilities. Trellix's research team develops these signatures and tests them thoroughly before releasing them to its customers.
There could be unique security requirements that would not be possible to be covered in the Trellix IPS-supplied signature set. For such cases, you have the option of developing your own attack definitions. Such user-defined attacks are referred to as custom attack definitions or custom attacks.