The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Import previously exported custom attacks

Prev Next

If you had exported any Trellix IPS Custom Attacks, you can import it back into the Manager. Note that this should be the same ZIP file that was created at the time of export. If this ZIP file contains any Snort Custom Attacks, those are imported as well. This feature enables you to import custom attack definitions created on a different Manager as well as the Trellix IPS-defined custom attacks.

Note

When you import the ZIP file containing the exported attack definitions, only the attacks not present in the Manager are imported.

To import the previously exported Trellix IPS Custom Attacks, perform the following steps:

  1. In the Custom Attack Editor, go to Other Actions → Import.

    GUID-008C690B-9B7D-4F86-9032-BB749A28B766-low.png
  2. Browse to the location of your saved Trellix IPS Custom Attack ZIP file.

  3. Click Open.

    The imported attacks are listed in a new tab in the Custom Attack Editor. If the ZIP contains Snort Custom Attacks, those two types of attacks are listed on separate tabs.

  4. If you are importing Native Custom Attacks:

    1. Select Import Native Trellix IPS Attacks.

      Import Native Trellix IPS Attacks
      Import Native Trellix IPS Attacks


    2. Deselect Import Snort Rules.

    3. Deselect Import Snort Macros.

    4. Deselect Import Snort Classification.

    5. Click Import.

    If you are importing Snort Rules:

    1. Deselect Import Native Trellix IPS Attacks.

    2. Select Import Snort Rules.

      Import Snort Rules
      Import Snort Rules


    3. Select Check For Overlaps With Existing Trellix IPS Attacks.

    4. Select a Protection Category value.

    5. Select Import Snort Macros.

    6. Select Import Snort Classification.

    7. Click Import.

  5. Verify if the attack is published in the policies.

  6. Publish the attack with its signatures to the Sensors for attack detection.