In case of Trellix IPS Custom Attacks, you can use multiple conditions and/or comparisons within a single attack definition to increase your confidence in detecting an unknown attack. There are many configuration possibilities; the procedure that follows details the following scenario:
One signature with two conditions. Both conditions must be met before an alert is generated.
The first condition has a single comparison.
The second condition employs an OR comparison; that is, either of the two comparisons in the condition signifies a positive match.
You can use various comparison methods within a condition. For example, if you employ two comparisons within a condition, one comparison can be a string match, while the second can be a fixed field check.
To create the Trellix IPS Custom Attack definition:
Open the Custom Attack Editor.
Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks