The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

How to block exploit traffic

Prev Next

Exploit refers to attacks that are discovered through a set of parameters, or rules, and matched against data within a packet. Signatures — specific strings used to match data in offending packets — are the key method in discovering an exploit. An attack can have multiple signatures; thus, enabling more than one chance at attack detection.

Using the Policy Editor, you can enable the blocking option for the required attacks.

The blocking of traffic for exploit works as follows:

  • The Sensor applies the configured inbound or outbound policy depending on the traffic direction, which is determined via the Sensor cabling and port configuration.

  • The Sensor analyzes the traffic and, based on the policy, determines whether the traffic is "good" (does not match an attack configured in the policy) or "bad" (matches an attack configured in the policy). If the traffic is bad, the Sensor then applies the configured "drop packets" action. When Trellix IPS identifies a malicious flow, it blocks only the flow; not all the traffic from the source IP address (Sensor behavior is unlike that of a firewall).

  • For UDP and ICMP traffic, only the attack packet is blocked. With TCP traffic, the entire attack flow is blocked; we recommend that you also configure a TCP Reset action in the policy to reset the flow.

    Note

    When inline, the TCP resets always go out the inline ports. Response ports are used when the device is configured for tap or span mode.