Traffic flows that are not identified as belonging to any particular protocol are passed to the Packet Search Protocol Specification Engine for further parsing. Trellix IPS presents each direction of the flow to Trellix IPS-defined attacks and to any Custom Attack Definitions. Tests against packet search traffic typically take the form of specific ordered pattern matches to prevent false positives and performance problems.
Packet searches
- Published on Oct 5, 2026
- 1 minute(s) read
Was this article helpful?