After you create a Custom Attack and the constituent signatures or rules, you need to save the attack in the Manager server for it to be published in every rule set where the attack definition fits one or more categories, rule set categorization that was configured as part of attack creation. When you apply a policy that includes a rule set containing your attack definition, detection of your attack is active.
Consider that when you created a Trellix IPS Custom Attack, you set the Severity to Medium and chose HTTP as the Exploit classification. Once exported, this attack is published in all rule sets that publish Medium-severity, HTTP attacks, such as the Default, Outside Firewall, and Web Server rule sets provided with Trellix IPS. (This also publishes any rule set that you have created which calls for HTTP attacks of Medium severity or higher.) When you apply a policy that publishes one of these rule sets, you are applying your Custom Attack for active searching and alerting upon detection.
When you save the custom attacks to the Manager server, only those attacks with State as Published are published in the rule sets. If you want to change the State of a custom attack, right click on it and select Published or Staged.
When you create a Trellix IPS Custom Attack, the State is set to Published by default. In case of Snort Custom Attacks, there are instances where the state is set to Staged. For example, if there is a Trellix IPS attack signature with the same CVE ID, the Manager sets the State to staged when you save the attack. The State is also set to staged if the Conversion Result is failed or warning.
Note
If after saving the Custom Attack to the Manager server, you import the attack back to the Custom Attack Editor, edit the file and make a name change to either the attack or a signature in the attack, then save it again in the Manager server, the name change will not take affect in any open Attack Log views. You must close all Attack Log windows and restart the Attack Log to see the name change upon attack detection.