If the Trellix IPS-supplied signature set is adequate to protect your network, then why create one yourself?
The reasons you might want to create an attack definition will vary widely based on the usage scenario for your IPS Sensor and the environment in which it is deployed. The sections below attempt to describe some common scenarios and the actions that might be taken when they occur.
Emergency situations - Trellix follows strict quality assurance processes and requires high-quality information before providing updates to customers. Thus, there may be situations where an attack covering particular vulnerabilities may be a very high priority for your network but might not be provided as swiftly as your security policy might require. In this case, you might need to write and deploy strategic attacks based on your knowledge of your network's vulnerabilities until an update from Trellix is available.
Forensic analysis - It may be useful to deploy specialized attacks to investigate suspicious activity on your network and possibly to track intrusions.
Custom attacks for Your particular environment - Writing custom attacks for your network environment may be necessary for a variety of reasons. The most common is policy enforcement. For example, your security policy may dictate that certain traffic or usage patterns are disallowed. In such cases, it may be useful to write and deploy attacks that can alert your IT or security staff.
To preserve legacy attack definitions - If you are migrating from an open-source IPS or IDS solution, such as Snort, you may want to import the attacks in their current format into Trellix IPS.