The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Manage attack set profiles

Prev Next

Attack Set Profiles enable the use of a powerful tool for defining the exact environment resources you want to protect. To recap, an attack set profile consists of select attacks specific to a network environment, such as the operating systems you employ, the installed applications (email, chat), and the transport and application protocols (HTTP, FTP) used for data delivery. The protocol field includes all of the attacks detected by Trellix IPS for specific selection by attack name, severity, and the chance a signature may trigger a false positive. Each rule you configure narrows the detection focus of your Sensor interfaces (where policy is applied) to provide the highest degree of detection accuracy and performance.

The Attack Set Profiles page provides the following functions:

  • Viewing an attack set profile

  • Adding an attack set profile

  • Cloning an attack set profile: Cloning duplicates an existing attack set profile, and is similar to a "save as" function. You can clone any attack set profile to further refine the parameters for the characteristics of a new environment. You can clone a provided attack set profile, save it under a new name, and customize it to meet the needs of your unique environment.

    Cloning a provided attack set profile specifically enables you to add/subtract from the default settings of an attack set profile. For example, you may not want to see alerts for Low severity attacks, thus you would clone and customize an attack set profile to reflect a minimum severity of 4 (Medium) for all attacks.

  • Editing an attack set profile: Editing an attack set profile allows you to make the changes necessary to better define the environment you will be monitoring. You can edit only the attack set profiles you have created; the preconfigured policies cannot be edited. Editing a user-created attack set profile permanently changes that attack set profile.

  • Deleting an attack set profile: You cannot delete currently applied attack set profiles and non-editable attack set profiles.