The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sensor response actions

Prev Next

Sensor actions are responses your Sensor enacts or sends through the network to prevent or deter further attacks.

  • Drop further packets (Inline mode only) — Dropping the specific attack packets is a key advantage of inline mode. When detecting inline (real time), the packets that trigger signatures and (optionally) all subsequent packets related to that connection can be dropped before they reach the intended target system. This capability provides true "intrusion prevention." This action is also known as "blocking."

  • Send an alert(default) — When traffic violates a Sensor policy, an alert is generated and sent to the Manager to be viewed using the Attack Log. Alerts can be examined for content and sorted by key fields, such as severity level, attack category, and so on. For more information on the Attack Log, see the Trellix Intrusion Prevention System Product Guide.

  • Quarantine— Sensor performs the quarantine of infected host, by isolating the host for a specified period.

  • Packet log — Sends a log or copy of the packet information to the Manager database; this information acts as a record of the actual flow of traffic that triggered the attack and can be used for detailed packet analysis. When the data is viewed in the Attack Log, the data is converted to libpcap format for presentation. Tools like Wireshark can be used to examine the packet log data for more detailed analysis of attack packet data. In the IPS Policy Editor/ Master Attack Repository, the user can specify how many packets should be logged or for what duration. You can also choose to encrypt the packet log channel via SSL to protect the packet log data.

  • TCP reset — For TCP connections only. TCP uses the RST (Reset) bit in the TCP header to reset a TCP connection. Resets are sent in response to a connection carrying traffic which violates the security policy of the domain. The user can configure reset packets to be sent to the source and/or destination IP address.

  • Ignore Rules — Creating ignore rule enables you to filter out alerts based on the source or the destination of the security event. For example, if you know that your IT department executes vulnerability scans from a particular IP address, you can filter events originating from that address. The ignore rule editor provides a convenient interface for creating ignore rules.

  • ICMP host unreachable — ICMP Host Unreachable packets can be sent in response to the source of UDP or ICMP attacks.