The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Response management

Prev Next

When a Sensor detects activity to be in violation of a configured policy, a preset response from the Sensor is integral to the protection or prevention process. Proper configuration of responses is crucial to maintaining effective protection. Critical attacks like buffer overflows and DoS attacks require responses in real time, while scans and probes can be logged and researched to determine compromise potential and the source of the attack. Developing a system of actions, alerts, and logs based on specific attacks or attack parameters (such as severity) is recommended for effective network security.

For example, since Trellix IPS can be customized to protect any zone in a network, knowing what needs to be protected can help to determine the response type. If monitoring outside of the firewall in Inline Mode, preventing DoS attacks and attacks against the firewall is crucial. Most other suspicious traffic intended for the internal network, including scans and low-impact well-known exploits, are best logged and analyzed as the impact is not immediate and a better understanding of the potential attack purpose can be determined. Thus, if you are monitoring outside of a firewall in Inline Mode, it is important to not set the policies and responses so fine that they disrupt the flow of traffic and slow down the system; rather, prevent the crippling traffic from disrupting your network.

Note

Setting a response type during policy configuration is critical for an effective intrusion management system.