You can use the predefined templates to create some of the commonly used Trellix IPS custom attacks. By using these templates, you can create effective Trellix IPS custom attacks even if you do not possess detailed knowledge of the related protocol, its header, or the syntax of Trellix IPS custom attacks.
Predefined templates are available to create Trellix IPS custom attacks that:
Detect a URL
Detect an email attachment file name
Detect a DNS query or response
Detect a string in an application running over a custom port
Detect a TCP connection attempt from a specific IP address
When you use the templates, a Trellix IPS custom attack with the relevant protocol is automatically created. Also, the corresponding signature is created for the attack. You can add more conditions to the signature or add more signatures to the Trellix IPS custom attack. For example, when you use the template to detect TCP connection attempts from specific IP addresses, the signature for the IP addresses that you specify is automatically created. To specify more IP addresses for this attack, create the corresponding signatures for those IP addresses.
Important
By default, the signatures that are created when you use the templates have high value of Benign Trigger Probability (BTP). You can edit this value post-creation. Note that the attacks of BTP value high are not published in the Default Detection and Default Prevention policies.
Note
When you save the Trellix IPS custom attacks in the Manager database, an informational fault is displayed in the Status page to indicate whether the custom attacks were successfully saved.