The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Structure of a Snort custom attack

Prev Next

A Snort Custom Attack is made up of one Snort rule. To define a Snort Custom Attack, you either write the Snort rule directly in the Custom Attack Editor or import it into the Editor from a file. The Sensor automatically creates the Snort Custom Attack record for each rule that you write or import.

When the Sensor creates the attack for a Snort rule, it automatically defines the values for fields such as attack name and attack severity. The following section explains how the Sensor defines the attack-level values for a Snort Custom Attack:

For the Attack Name, the format that the Sensor uses for the name is SNORT:<the text specified for the msg rule option in the rule>(<SID>). So, this name is modified accordingly if you modify the msg text or the SID of the rule.

Note

msg rule option and a unique SID are mandatory for a Snort Custom Attack.

Blocking is set to attack packet for all Snort Custom Attacks. You cannot modify this.

On the Impact tab, the Severity is based on the classtype keyword or the priority tag. Each classtype has a default priority defined. Typically, the classtypes with the default priority values are defined in the classification.config file. If a rule has both classtype keyword and priority tag, the severity is based on the priority tag.

The Sensor assigns the severity for a Snort custom attack based on the following:

  • A priority 1 Snort attack definition is assigned a severity of High.

  • A priority 2 Snort attack definition is assigned a severity of Medium.

  • A priority of 3 or higher is assigned a severity of Low.

When you modify the classtype or the priority tag value of a rule, the Sensor will also modify the severity accordingly. This means when you save the attack to the Sensor server, the rule sets (and policies) in which the attack was published may change.

For the Exploit category, tcpip-machine is selected as the package with any as the OS. You cannot add, delete, or modify any impact package or protocol for Snort Custom Attacks.