The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Signatures and rules

Prev Next

Important

Disclaimer: This content was written in English. In the event of any differences between the English content and the translation, always refer to the English source. Some content has been translated with Google machine translation tools.

A signature or rule is a set of checks (for example, string matches or IP-port comparisons) that are applied to network traffic seen by the Sensor. The term signature is relevant for Trellix IPS Custom Attacks (that is, custom attacks in Trellix IPS format) or the Trellix IPS-supplied signature set. The term rule applies to Snort Custom Attacks.

In case of Snort Custom Attacks, the Manager parses them to check the syntax. Then it converts the valid attack definitions to Trellix IPS's format and saves them in the Manager database. Once in the database, the converted Snort rules function like any other Trellix IPS signature. So, in Trellix IPS, both signatures and rules are functionally similar. What applies to a signature is also applicable to a rule unless stated otherwise.

Note

Throughout this guide, Snort Custom Attacks are also referred to as Snort rules or just rules. This is not to be confused with the Trellix IPS rule sets, which are a collection of attack definitions that meet certain criteria.

The attack detection mechanism in Trellix IPS relies on comparison of traffic to a database of signatures or rules. Trellix IPS enables you to define checks using combinations of string matches and checks for other anomalies such as excessive field lengths. When all the necessary conditions for a given rule of set of signatures are satisfied, an event is raised in the Sensor; all signatures and rules defined are checked against the traffic simultaneously and all matching events within the context of a given attack are correlated by the Sensor to generate a single alert.