The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get all Attacks

Prev Next

This URL gets all available attack definitions in the Manager.

Resource URL

GET /attacks/

Request Parameters

URL Parameters: None

Field Name

Description

Data Type

Mandatory

attack_id

Unique attack id

String

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

AttackDescriptorDetailsList

List of attacks with basic information of each attack

Array

Details of object in AttackDescriptorDetailsList:

Field Name

Description

Data Type

attackId

Attack NSP id

String

name

Attack name

String

DosDirection

Attack direction, can be

"INBOUND" /

"OUTBOUND" /

"BOTH"

String

Severity

Attack severity, number between 0 and 9

Number

description

Attack details

Object

Details of description:

Field Name

Description

Data Type

definition

Attack definition

String

btp

BTP

String

rfSB

RFSB

String

protectionCategory

Protection category

String

target

Attack target

String

httpResponseAttack

HTTP response attack

String

priority

Priority

String

protocols

Protocols

String

attackCategory

Attack category

String

attackSubCategory

Attack sub category

String

snortEngine

Snort engine

String

versionAdded

Signature set version in which the attack was added

String

versionUpdated

Recent signature set version in which the attack was updated

String

reference

References

Object

signatures

Signatures

Array

componentAttacks

Component attacks

Array

comments

Comments

Object

Details of reference:

Field Name

Description

Data Type

nspId

NSP id

String

cveId

CVE id list

String

microsoftId

Microsoft id list

String

bugtraqId

Bug Ttaq id list

String

certId

Cert id list

String

arachNidsId

ArchNid id list

String

additionInfo

Any additional info

String

Details of object under signatures:

Field Name

Description

Data Type

name

Signature name

String

conditions

List of conditions

List of string

Details of object under componentAttacks:

Field Name

Description

Data Type

nspId

NSP id

String

attackName

Attack name

String

Details of comments:

Field Name

Description

Data Type

comments

Comments

String

availabeToChildDomains

Available to child domains or not

Boolean

parentDomainComments

Parent domain comments

String

Example

Request

GET https://<NSM_IP>/sdkapi/attacks

Response

  {
"AttackDescriptorDetailsList": [
	...
{
                "DosDirection": null,
                "Severity": 5,
                "attackId": "0x00000100",
                "name": "IP: IP Fragment too Large",
                "description": {
                    "definition": "The Fragment offset plus the length exceeds 65,535. This generic condition indicates either errors in some network hardware/software, or maliciously constructed fragmented packets.\n\nnull\n\nnull\n\nnull\n\nSoftware Packages <br>any Internet connected machine<ul></ul>",
                    "btp": "Low",
                    "rfSB": "No",
                    "protectionCategory": "[Network Protection/IP]",
                    "target": "Server",
                    "httpResponseAttack": "No",
                    "priority": "High",
                    "protocols": "ipv4",
                    "attackCategory": "Exploit",
                    "attackSubCategory": "Protocol Violation",
                    "snortEngine": "---",
                    "versionAdded": "10.8.10.6",
                    "versionUpdated": "10.8.10.6",
                    "reference": {
                        "nspId": "0x00000100",
                        "cveId": "",
                        "microsoftId": "",
                        "bugtraqId": "",
                        "certId": "",
                        "arachNidsId": "",
                        "additionInfo": null
                    },
                    "signatures": [
                        {
                            "name": "Signature#1",
                            "conditions": [
                                "condition 1",
                                " System Event Name=\"ip-fragment-too-large\" "
                            ]
                        }
                    ],
                    "componentAttacks": [],
                    "comments": {
                        "comments": "",
                        "availabeToChildDomains": true,
                        "parentDomainComments": null
                    }
                }
            }
...
]
}

Error Information

Following error code is returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

500

1001

Internal error