The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Matching Criteria section

Prev Next

The Matching Criteria section enables you to categorize your attack for eventual submission to your Manager's attack database. Once exported to the attack database, selection of your attack is published by one of several rule sets, which are then added to policies for enforcement.

A rule set is defined as a set of ordered rules used to determine what attacks or conditions are of interest, and thus should be monitored when applied as part of a policy. A rule set is configured based on attack category (Exploit, Reconnaissance), operating system (Windows, UNIX), protocol (HTTP, DNS), application (SendMail, Apache), severity (High, Low), and benign trigger probability (High, Low) options. Except for benign trigger probability, you need to indicate these options when defining at the attack level. You can indicate the value for benign trigger probability when creating the signatures for an attack definition. Based on the values that you set for these options, the attack is available for policy enforcement.

  • Protocol — This is the identified impact protocol for the Snort Custom Attack.

  • Software Package (OS) — Manager assigns tcpip-machine to all Snort Custom Attacks. You cannot edit this value.