It is imperative that you thoroughly test your attack definitions before deploying them in a production environment. Incorrect definitions can lead to false positives, false negatives, and performance problems, any of which could be very detrimental to the security and reliability of your network. The best way to avoid these problems is to make use of a comprehensive test plan that puts the attack definition through the full deployment process and verifies that it performs as expected.
Trellix recommends that at a minimum you include the following verification exercises in your test plan:
Use traffic generation tools or packet dumps to verify that your attack definitions match the traffic they are supposed to detect.
If possible, verify that any custom attack definition is not duplicating functionality already available in Trellix IPS. For example, check if there is Trellix IPS-supplied attack definition for the same condition. You can do this by examining whether your test traffic raises duplicate alerts - one for Trellix IPS-supplied attack and another for custom attack.
Deploy the custom attacks on a non-production Sensor connected to either a test network that mirrors your production network traffic or a non-production Sensor connected to your production network in SPAN or Tap mode.