The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Custom attacks export

Prev Next

You can export all the Trellix IPS Custom Attacks, Snort Custom Attacks, and custom-defined grep protocols in the Manager to a ZIP file. The export feature enables you to use the custom attacks on a different Manager without having to recreate them. Trellix strongly recommends that you do not try to modify the exported attack files and then re-import them.

In the exported ZIP file:

  • The Trellix IPS Custom Attacks are stored in the attacks.xml file.

  • The packet grep protocols are stored in the pktgrepprotocol.xml file.

  • The Snort Custom Attacks are exported in the Snort format.

  • The Snort Custom Attacks Rules and the related data such as variables that you imported are stored in correspondingly named files. For example, assume that you had imported rules from ftp.rules file. When you export, these rules are stored in ftp.rules file within the ZIP.

  • The rules that you directly created in the Editor are contained in unknown.rules file.

    Note

    There is no option to export just the Trellix IPS Custom Attacks or just the Snort Custom Attacks. When you export, all custom attacks listed in the All Custom Attacks tab and the custom-defined packet grep protocols are exported.