The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Preconfigured attack set profiles

Prev Next

Trellix supplies a set of preconfigured attack set profiles that correspond to the preconfigured IPS policies as well. You can use these attack set profiles to create specific IPS policies according to your requirements. That is, you can clone these attack set profiles and modify them to create custom IPS Policies. These pre-defined attack set profiles are available in the Attack Set Profiles page, which you can access from the Policy tab.

Attack set profiles

Designed to Protect Against:

Default Detection

All attacks.

Default DoS and Reconnaissance Only

All signatures are disabled by default. This policy is provided for the scenario where a substream of traffic needs to be ignored by the IPS.

Default Exclude Informational

All attacks, including those with known noisy signatures, but omitting Informational severity attacks. This policy differs from Default as it alerts for every attack in the Trellix IPS database, including those with noisy signatures. This enables expert security personnel to fully analyze their network traffic. Informational "attacks" are not enabled.

Default Prevention

All attacks and Trellix-recommended blocking of selected attacks

Default Testing

Similar to above, with the exception that Informational-level alerts are included.

DMZ

All attack types except for those exploits using TFTP, Telnet, RIP, NETBIOS, NFS, and WINS.

DNS Server

All Reconnaissance and DoS attacks, generic backdoors, and exploits using the DNS protocol.

File Server

All Reconnaissance and DoS attacks, generic backdoors, and exploits using DNS, NFS/RPC, and NETBIOS/SMB protocols.

Inside Firewall

All attack types except for those exploits using TFTP, Telnet, and RIP.

Internal Segment

All attacks except for exploits using RIP and routing protocol attacks.

Linux Server

All attacks where the impacted operating system includes Linux.

Mail Server

All Reconnaissance and DoS attacks, generic backdoors, and exploits using DNS, SMTP, POP3, and IMAP protocols.

Outside Firewall

All attacks except for Reconnaissance category.

Solaris Server

All attacks where the impacted operating system includes Solaris.

UNIX Family

UNIX Server

All attacks where the impacted operating system includes UNIX.

Web Server

All Reconnaissance and DoS attacks, generic backdoors, and exploits using DNS, HTTP, and FTP protocols.

Windows and Solaris Server

All attacks where the impacted operating system includes Windows or Solaris.

Windows and UNIX Server

All attacks where the impacted operating system includes Windows or UNIX.

Windows Family

Windows Server

All attacks where the impacted operating system includes Windows.

Windows, Linux, and Solaris Server

All attacks where the impacted operating system includes Windows, Linux, or Solaris.