You can add an attack to the Master Attack Repository policy set. This is a default generic policy which is applied across multiple Sensors. Hence, all the Sensors are updated with the attack. To add the attack to the policy:
Steps:
Navigate to Analysis → <Admin Domain Name> → Attack Log.
Select the alert, click Other Actions at the bottom of the page.
Select Update Policy, and click (Global IPS) Master Attack Repository for IPS devices or Master NTBA for NTBA appliances.
The <Attack Name> panel opens.
Make the required changes to the policy settings and click Update.
The attack is added to the Master Attack Repository policy set.
Global policy update.png)
To view or edit the attack added to the Master Attack Repository policy set:
Navigate to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS.
Double-click the Master Attack Repository policy.
You can view the attack added to the list under Attack Definitions tab.