The Trellix IPS supports the Trellix IPS Snort and the Suricata Snort. This section provides information on how to create and maintain Trellix IPS Snort and Suricata custom attacks. In Trellix IPS, you can create the custom attacks in one of two ways:
Construct the Snort rules, one at a time, directly in the Custom Attack Editor.
Construct multiple Snort rules in a file and import the file into the Manager. You may want to consider this method when you have a large number of attack definitions to create or if you want to use the Snort rules from a source such as the Snort user community.
Important
Before you create custom attacks, make sure you have reviewed and understood the considerations and best practices to be followed when using Snort rules in Trellix IPS.