Signature set is a comprehensive set of attack definitions developed and provided by Trellix Advanced Research Center. An attack definition contains one or more signatures, which indicate suspicious or malicious activity. These signatures are then matched against traffic passing through the Sensor monitoring ports.
Each attack definition can be configured to perform response actions like sending an alert to the Manager, dropping traffic, capturing packets, or generating an email. It is used to detect threats and anomalies in the network traffic.
Signature sets are available in Trellix IPS Update Server (Update Server). Trellix regularly updates the signature set with latest attack definitions which you can download from the Update Server.
The threat landscape is constantly evolving, and new attacks are regularly added to the signature set to keep the network protection up-to-date. The attack definitions in the signature set are categorized as high, medium, and low priority attacks. This helps optimize Sensor resources on older Sensor models and Sensors running older software versions, thereby protecting against the most critical and relevant attacks.
Based on the priority attribute configured for the Sensor models, the Manager dynamically compiles the signature set using the current signature set version available in the Manager. The corresponding set of attack definitions are then pushed to the Sensors.
For more information about downloading signature sets, see the Download signature set updates.