The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Menu items

Prev Next

This section describes the menu options that are available in Custom Attack Editor.

File menu
File menu


Option

Definition

Applicable to Native Trellix IPS Format and Snort Format

GUID-F3F18CF8-B95D-4C8C-8DB8-996CDB6087FB-low.png

Click to define a custom attack. You can either create an exploit attack or a reconnaissance attack. You need to create an attack before adding signatures to it.

GUID-717A81EC-A913-4C2F-B61C-0129ED30387A-low.png

Click to copy an existing custom attack.

GUID-15AADF4D-7927-4A0E-96E9-69CF820F0712-low.png

Click to delete the selected attack from the Manager client. To delete it from the Manager server, you need to click Save after you delete it from the client.

Export

Select this option to export the custom attacks in the Manager to a file.

Test Compile

Click to Test Compile the selected custom attacks.

Import

Select this menu to import Native Trellix IPS Format or Snort Format custom attack from files to the Manager.

Check Attack Counts

Click to view the count of published custom attacks.

Export All

Click to export all the custom attacks in the Manager to a file.

Manage Grepping Protocols

Click to Manage Grepping Protocols.

Save as CSV

Click to save the custom attacks in CSV format.

Applicable to Snort Format

Snort Variables

Click to manage Snort Variables.

Important

Before you delete a custom-defined protocol, make sure it is not used in any of the Trellix IPS Custom Attacks.