The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get all Attacks

Prev Next

This URL gets all available attack definitions in the Manager.

Resource URL

GET /attacks/

Request Parameters

URL Parameters: None

Field Name Description Data Type Mandatory
attack_id Unique attack id String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
AttackDescriptorDetailsList List of attacks with basic information of each attack Array

Details of object in AttackDescriptorDetailsList:

Field Name Description Data Type
attackId Attack NSP id String
name Attack name String
DosDirection Attack direction, can be

"INBOUND" /

"OUTBOUND" /

"BOTH"

String
Severity Attack severity, number between 0 and 9 Number
description Attack details Object

Details of description:

Field Name Description Data Type
definition Attack definition String
btp BTP String
rfSB RFSB String
protectionCategory Protection category String
target Attack target String
httpResponseAttack HTTP response attack String
priority Priority String
protocols Protocols String
attackCategory Attack category String
attackSubCategory Attack sub category String
snortEngine Snort engine String
versionAdded Signature set version in which the attack was added String
versionUpdated Recent signature set version in which the attack was updated String
reference References Object
signatures Signatures Array
componentAttacks Component attacks Array
comments Comments Object

Details of reference:

Field Name Description Data Type
nspId NSP id String
cveId CVE id list String
microsoftId Microsoft id list String
bugtraqId Bug Ttaq id list String
certId Cert id list String
arachNidsId ArchNid id list String
additionInfo Any additional info String

Details of object under signatures:

Field Name Description Data Type
name Signature name String
conditions List of conditions List of string

Details of object under componentAttacks:

Field Name Description Data Type
nspId NSP id String
attackName Attack name String

Details of comments:

Field Name Description Data Type
comments Comments String
availabeToChildDomains Available to child domains or not Boolean
parentDomainComments Parent domain comments String

Example

Request

GET https://<NSM_IP>/sdkapi/attacks

Response

 {
"AttackDescriptorDetailsList": [
	...
{
                "DosDirection": null,
                "Severity": 5,
                "attackId": "0x00000100",
                "name": "IP: IP Fragment too Large",
                "description": {
                    "definition": "The Fragment offset plus the length exceeds 65,535. This generic condition indicates either errors in some network hardware/software, or maliciously constructed fragmented packets.\n\nnull\n\nnull\n\nnull\n\nSoftware Packages <br>any Internet connected machine<ul></ul>",
                    "btp": "Low",
                    "rfSB": "No",
                    "protectionCategory": "[Network Protection/IP]",
                    "target": "Server",
                    "httpResponseAttack": "No",
                    "priority": "High",
                    "protocols": "ipv4",
                    "attackCategory": "Exploit",
                    "attackSubCategory": "Protocol Violation",
                    "snortEngine": "---",
                    "versionAdded": "10.8.10.6",
                    "versionUpdated": "10.8.10.6",
                    "reference": {
                        "nspId": "0x00000100",
                        "cveId": "",
                        "microsoftId": "",
                        "bugtraqId": "",
                        "certId": "",
                        "arachNidsId": "",
                        "additionInfo": null
                    },
                    "signatures": [
                        {
                            "name": "Signature#1",
                            "conditions": [
                                "condition 1",
                                " System Event Name=\"ip-fragment-too-large\" "
                            ]
                        }
                    ],
                    "componentAttacks": [],
                    "comments": {
                        "comments": "",
                        "availabeToChildDomains": true,
                        "parentDomainComments": null
                    }
                }
            }
...
]
} 
 

Error Information

Following error code is returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 500 1001 Internal error