You can export all the Trellix IPS Custom Attacks, Snort Custom Attacks, and custom-defined grep protocols in the Manager to a ZIP file. The export feature enables you to use the custom attacks on a different Manager without having to recreate them. Trellix strongly recommends that you do not try to modify the exported attack files and then re-import them.
In the exported ZIP file:
The Trellix IPS Custom Attacks are stored in the attacks.xml file.
The packet grep protocols are stored in the pktgrepprotocol.xml file.
The Snort Custom Attacks are exported in the Snort format.
The Snort Custom Attacks Rules and the related data such as variables that you imported are stored in correspondingly named files. For example, assume that you had imported rules from ftp.rules file. When you export, these rules are stored in ftp.rules file within the ZIP.
The rules that you directly created in the Editor are contained in unknown.rules file.
Note
There is no option to export just the Trellix IPS Custom Attacks or just the Snort Custom Attacks. When you export, all custom attacks listed in the All Custom Attacks tab and the custom-defined packet grep protocols are exported.