The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Get Attack Details

Prev Next

This URL gets details for a particular attack.

Resource URL

GET /attack/<attack_id>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

attack_id

Unique attack id

String

Yes

Response Parameters

Following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

AttackDescriptor

Basic attack information

Object

Details of AttackDescriptor:

Field Name

Description

Data Type

attackId

Attack id

String

name

Attack name

String

DosDirection

Attack direction, can be

"INBOUND" /

"OUTBOUND" /

"BOTH"

String

Severity

Attack severity, number between 0 and 9

Number

description

Attack details

Object

Details of description:

Field Name

Description

Data Type

definition

Attack definition

String

btp

BTP

String

rfSB

RFSB

String

protectionCategory

Protection category

String

target

Attack target

String

httpResponseAttack

HTTP response attack

String

priority

Priority

String

protocols

Protocols

String

attackCategory

Attack category

String

attackSubCategory

Attack sub category

String

snortEngine

Snort engine

String

versionAdded

Signature set version in which the attack was added

String

versionUpdated

Recent signature set version in which the attack was updated

String

reference

References

Object

signatures

Signatures

Array

componentAttacks

Component attacks

Array

comments

Comments

Object

Details of reference:

Field Name

Description

Data Type

nspId

NSP id

String

cveId

CVE did list

String

microsoftId

Microsoft id list

String

bugtraqId

Bug traq id list

String

certId

Cert id list

String

arachNidsId

ArchNid id list

String

additionInfo

Any additional info

String

Details of object under signatures:

Field Name

Description

Data Type

name

Signature name

String

conditions

List of conditions

List of string

Details of object under componentAttacks:

Field Name

Description

Data Type

nspId

NSP id

String

attackName

Attack name

String

Details of comments:

Field Name

Description

Data Type

comments

Comments

String

availabeToChildDomains

Available to child domains or not

Boolean

parentDomainComments

Parent domain comments

String

Example

Request

GET https://<NSM_IP>/attack/0x00000100

Response

{
"AttackDescriptor": 
{
                "DosDirection": null,
                "Severity": 5,
                "attackId": "0x00000100",
                "name": "IP: IP Fragment too Large",
                "description": {
                    "definition": "The Fragment offset plus the length exceeds 65,535. This generic condition indicates either errors in some network hardware/software, or maliciously constructed fragmented packets.\n\nnull\n\nnull\n\nnull\n\nSoftware Packages <br>any Internet connected machine<ul></ul>",
                    "btp": "Low",
                    "rfSB": "No",
                    "protectionCategory": "[Network Protection/IP]",
                    "target": "Server",
                    "httpResponseAttack": "No",
                    "priority": "High",
                    "protocols": "ipv4",
                    "attackCategory": "Exploit",
                    "attackSubCategory": "Protocol Violation",
                    "snortEngine": "---",
                    "versionAdded": "10.8.10.6",
                    "versionUpdated": "10.8.10.6",
                    "reference": {
                        "nspId": "0x00000100",
                        "cveId": "",
                        "microsoftId": "",
                        "bugtraqId": "",
                        "certId": "",
                        "arachNidsId": "",
                        "additionInfo": null
                    },
                    "signatures": [
                        {
                            "name": "Signature#1",
                            "conditions": [
                                "condition 1",
                                " System Event Name=\"ip-fragment-too-large\" "
                            ]
                        }
                    ],
                    "componentAttacks": [],
                    "comments": {
                        "comments": "",
                        "availabeToChildDomains": true,
                        "parentDomainComments": null
                    }
                }
            }
}

Error Information

Following error codes are returned by this URL:

S.No

HTTP Error Code

SDK API errorId

SDK API errorMessage

1

500

1001

Internal error

2

404

1402

Invalid attack id