The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Technical information references

Prev Next

A Custom Attack definition is generally based on an advisory or some other description of a known vulnerability. You should have in hand whatever information you can find regarding the attack definition. This can include traffic dumps of an attack in progress or the exploit code itself. You can use this information to determine the characteristics of the vulnerability.

You should know the specific criteria that the attack definition should comprise of, such as field values and patterns to match. Your research may lead to a long list of characteristics specific to the exploit traffic. However, bear in mind that an attack definition based on all suspicious characteristics may be too specific. Although it would be precise, it may impact a Sensor's throughput or lead to detection problems. On the other hand, an attack definition based on only one of the characteristics may be too broad and generate false positives.