The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Required information for creating a custom attack

Prev Next

The following is a list of the information you should have in hand as you create your custom attacks and the constituent signatures or rule. A signature or rule can range from very simple (for example, checking the value of a header field) to highly complex checks of different information in a specific order. You must have good bit of data to aid yourself in creating an accurate attack definition, such as the following:

  • Reason for creating this custom attack

  • Technical information references for this custom attack

  • Protocol in which this custom attack will search the traffic (also known as the impact protocol)

  • Specific hardware or software platforms affected by this traffic (also known as impact packages)

  • Severity of this event

  • The direction in which the "traffic to be watched for" occurs

  • Specific criteria that comprise the attack, such as field values and patterns to match

  • A method, data, or tool to be used for testing the attack before you use it in your production environment