The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Attack Details

Prev Next

This URL gets details for a particular attack.

Resource URL

GET /attack/<attack_id>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
attack_id Unique attack id String Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name Description Data Type
AttackDescriptor Basic attack information Object

Details of AttackDescriptor:

Field Name Description Data Type
attackId Attack id String
name Attack name String
DosDirection Attack direction, can be

"INBOUND" /

"OUTBOUND" /

"BOTH"

String
Severity Attack severity, number between 0 and 9 Number
description Attack details Object

Details of description:

Field Name Description Data Type
definition Attack definition String
btp BTP String
rfSB RFSB String
protectionCategory Protection category String
target Attack target String
httpResponseAttack HTTP response attack String
priority Priority String
protocols Protocols String
attackCategory Attack category String
attackSubCategory Attack sub category String
snortEngine Snort engine String
versionAdded Signature set version in which the attack was added String
versionUpdated Recent signature set version in which the attack was updated String
reference References Object
signatures Signatures Array
componentAttacks Component attacks Array
comments Comments Object

Details of reference:

Field Name Description Data Type
nspId NSP id String
cveId CVE did list String
microsoftId Microsoft id list String
bugtraqId Bug traq id list String
certId Cert id list String
arachNidsId ArchNid id list String
additionInfo Any additional info String

Details of object under signatures:

Field Name Description Data Type
name Signature name String
conditions List of conditions List of string

Details of object under componentAttacks:

Field Name Description Data Type
nspId NSP id String
attackName Attack name String

Details of comments:

Field Name Description Data Type
comments Comments String
availabeToChildDomains Available to child domains or not Boolean
parentDomainComments Parent domain comments String

Example

Request

GET https://<NSM_IP>/attack/0x00000100

Response

{
"AttackDescriptor": 
{
                "DosDirection": null,
                "Severity": 5,
                "attackId": "0x00000100",
                "name": "IP: IP Fragment too Large",
                "description": {
                    "definition": "The Fragment offset plus the length exceeds 65,535. This generic condition indicates either errors in some network hardware/software, or maliciously constructed fragmented packets.\n\nnull\n\nnull\n\nnull\n\nSoftware Packages <br>any Internet connected machine<ul></ul>",
                    "btp": "Low",
                    "rfSB": "No",
                    "protectionCategory": "[Network Protection/IP]",
                    "target": "Server",
                    "httpResponseAttack": "No",
                    "priority": "High",
                    "protocols": "ipv4",
                    "attackCategory": "Exploit",
                    "attackSubCategory": "Protocol Violation",
                    "snortEngine": "---",
                    "versionAdded": "10.8.10.6",
                    "versionUpdated": "10.8.10.6",
                    "reference": {
                        "nspId": "0x00000100",
                        "cveId": "",
                        "microsoftId": "",
                        "bugtraqId": "",
                        "certId": "",
                        "arachNidsId": "",
                        "additionInfo": null
                    },
                    "signatures": [
                        {
                            "name": "Signature#1",
                            "conditions": [
                                "condition 1",
                                " System Event Name=\"ip-fragment-too-large\" "
                            ]
                        }
                    ],
                    "componentAttacks": [],
                    "comments": {
                        "comments": "",
                        "availabeToChildDomains": true,
                        "parentDomainComments": null
                    }
                }
            }
} 
 

Error Information

Following error codes are returned by this URL:

S.No HTTP Error Code SDK API errorId SDK API errorMessage
1 500 1001 Internal error
2 404 1402 Invalid attack id