The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Tab regions

Prev Next

To enable easy viewing, Custom Attacks are listed in tabbed regions in the Custom Attack Editor. The Native Trellix IPS Format tab is the default tab that is displayed when you launch the Custom Attack Editor. It displays all the Native Trellix IPS Format custom attacks. The Snort Format tab displays all the Snort Custom Attacks.

You can click on a column heading and drag-and-drop it to suit your viewing preference. Click on the arrow at the end of the column heading to:

  • Hide the column

  • Display any hidden columns

  • Sort or filter the contents in the column

GUID-79B41356-A84C-46C9-B488-9FF07D4BACEA-low.png

Note

What you see in the figure below are the default column headings.

Tab regions
Tab regions


Tab regions

Item

Description

Trellix IPS ID

When you save the added/imported custom attacks to the database, the Manager assigns a unique attack ID to each rule. For native Trellix IPS attacks, the ID starts with 0xc and for Snort attacks, it starts with 0xe.

Note

Until you save the newly-added attacks to the Manager database, they are assigned the same temporary ID.

SID

Snort rule ID (SID) is the ID assigned to a Snort rule by you or the party that provided the rule. The Snort attack definitions that you want to save in the Trellix IPS database must have a unique SID. Make sure that the SIDs of the attacks that you are writing or importing have not been used by the definitions that are already in the database.

For attack definitions that failed to import, the Trellix IPS assigns -1 as the SID.

Trellix IPS Snort Engine

The imported rules are available for both the Trellix IPS Snort and the Suricata Snort. This column indicates whether the rule was validated successfully.

Some rules may have been converted but with warnings. For example, rules for which an equivalent Trellix IPS signature exists are converted with warnings.

Some rules may have failed to convert. For example, rules that use undefined variables fail to convert.

The Validation field displays status of attack validation from the Trellix IPS Snort Engine. Validation results can be Success, Failed, or Warning.

The Test Compile column displays the status of test compilation.

Suricata Snort Engine

The Validation column displays status of attack validation from the Suricata Snort Engine.

Validation results for the Suricata Snort rules can be Success or Failed.

Last Updated Time

This is the time stamp when a rule was imported or modified.

State

This column indicates whether a rule will be published and therefore made available for inclusion in the IPS policies. You can click on a rule to publish or stage it.

Note

  • If you publish a Snort rule that overlaps with a native Trellix IPS attack definition, you can expect two alerts to be generated for the same rule.

  • Only the Published rules are considered for inclusion in the IPS policies. For more information, see the tables Rules for determining the state of a Custom Attack in Native Trellix IPS format and Rules for determining the state of a Custom Attack in Snort format below.

Name

The name for the attack that the Manager assigns post-import. The format that the Manager uses for the name is SNORT:<the text specified for the msg rule option in the rule> (<SID>). So this name is modified accordingly if you modify the msg text or the SID of the rule.

Note that msg rule option and a unique SID are required in a rule for you to import it into the Manager.

Severity

The Manager assigns a severity of Low, Medium, or High based on the priority value of the rule.

  • A priority 1 Snort attack definition is assigned a severity of High.

  • A priority 2 Snort attack definition is assigned a severity of Medium.

  • A priority of 3 or higher is assigned a severity of Low.

You can set the priority for a rule by using the priority keyword in the rule definition. If the priority keyword is not present in the rule, the Manager derives the priority value based on the classtype of the rule. However, if the classtype is not available for the rule and there is no priority set in the rule definition, the Manager assigns a priority value of 0 to the rule.

Tip

Severity is often used in attack set profiles to include/exclude attacks from IPS policies. To ensure inclusion of a rule in a policy, assign a Severity value as per the policy profile settings.

BTP (Benign Trigger Probability)

This column indicates the possibility of producing false positives. The lower the BTP value, higher is the accuracy of the rule.

Tip

BTP is often used in attack set profiles to include/exclude attacks from IPS policies. To ensure inclusion of a rule in a policy, assign a BTP value as per the policy profile settings.

Attack Target

This column indicates the type of attack target such as client, server, and so on.

Test Compile

This column indicates the compilation status of the attack.

Attack Category

This column indicates the category of the attack such as malware, exploit, policy violation, and so on.

Protection Category

Indicates the Protection Category to which the Trellix IPS Custom Attack belongs. You specify this when you create a Trellix IPS Custom Attack.

Supported Device Types

This column indicates the supported devices for the Snort Rule.



Note

The columns SID, Trellix IPS Snort Engine, and Suricata Snort Engine are available only on the Snort Format tab.

Rules for determining the state of a Custom Attack in Native Trellix IPS format

State of the Custom Attack

Trellix IPS Snort Engine Validation Status

Test Compile Status

Published

Success

Success

Published

Warning

Success

Staged

Warning

Failed

Staged

Failed

Pending

Staged

Success

Failed



Rules for determining the state of a Custom Attack in Snort format

State of the Custom Attack

Trellix IPS Snort Engine Validation Status

Test Compile Status

Suricata Engine Validation Status

Published

Success

Success

Success

Published

Success

Failed

Success

Published

Success

Success

Failed

Published

Failed

Pending

Success

Published

Warning

Success

Success

Published

Warning

Failed

Success

Staged

Warning

Success

Failed

Staged

Warning

Failed

Failed

Staged

Failed

Pending

Failed

Staged

Success

Failed

Failed