The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Custom-defined packet grep protocols

Prev Next

Custom-defined packet grep protocols section is where you can view the list of custom-defined packet grep protocols and also create new ones. Custom-defined packet grep protocols can be used when creating a Native Trellix IPS Format custom attack with Text in Custom Application template.

  • GUID-BA911B8C-BF48-439A-A7A8-4476AB282C7C-low.png
    — Add a new packet grep protocol instance.
  • GUID-03CC53E7-24D5-4E0B-AEC5-FEA60632DC36-low.png — Delete a created instance.

    Note

    You cannot modify a default custom-defined packet grep protocol.

    Custom-defined Packet Grep Protocols window
    Custom-defined Packet Grep Protocols window


When you add a packet grep protocol, you need to specify the transport layer protocol and the identifying port(s) for locating those attacks that use an application protocol unknown to Trellix IPS.

The interface fields and options are as follows:

  • Name — Name displayed during selection. For example, type "Custom-Adobe-Flash" for the Name.

  • Transport Protocol — Specify the transport protocol that will be used by the application whose protocol details that you are defining.

    • TCP

    • UDP

  • Ports — Target ports that have been added for the current custom protocol. Type the number in this field, and then click Add to add a port that can be used to identify the unknown traffic.

    Note

    Do not enter any standard port number.