The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Templates for Trellix IPS custom attacks

Prev Next

You can use the predefined templates to create some of the commonly used Trellix IPS custom attacks. By using these templates, you can create effective Trellix IPS custom attacks even if you do not possess detailed knowledge of the related protocol, its header, or the syntax of Trellix IPS custom attacks.

Predefined templates are available to create Trellix IPS custom attacks that:

  • Detect a URL

  • Detect an email attachment file name

  • Detect a DNS query or response

  • Detect a string in an application running over a custom port

  • Detect a TCP connection attempt from a specific IP address

When you use the templates, a Trellix IPS custom attack with the relevant protocol is automatically created. Also, the corresponding signature is created for the attack. You can add more conditions to the signature or add more signatures to the Trellix IPS custom attack. For example, when you use the template to detect TCP connection attempts from specific IP addresses, the signature for the IP addresses that you specify is automatically created. To specify more IP addresses for this attack, create the corresponding signatures for those IP addresses.

Important

By default, the signatures that are created when you use the templates have high value of Benign Trigger Probability (BTP). You can edit this value post-creation. Note that the attacks of BTP value high are not published in the Default Detection and Default Prevention policies.

Note

When you save the Trellix IPS custom attacks in the Manager database, an informational fault is displayed in the Status page to indicate whether the custom attacks were successfully saved.