The rule options section is the more critical section of a Snort rule. The rule options are to be separated by a semicolon. In a rule option, the keyword and argument are separated by a colon.
Rule options fall into one of the following categories:
General: These options contain the metadata for the rule but have no effect on attack detection.
Payload: These options look for data inside the packet payload and can be interrelated.
Non-payload: These options look for non-payload data.
Post-detection: These options indicate what happens when an attack is detected. These options are not relevant in Trellix IPS. Instead, you can configure the response actions in the IPS Policy Editor.