The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Trellix IPS Snort

Prev Next

Consider the following factors when selecting the Trellix IPS Snort engine:

  • The NS-series Sensors can support up to 5000 Snort rules. If you require support for more rules, contact Trellix Support.

  • \X, \P, \K, \U, \R, and \C escape sequences and backreferences are not supported.

  • Isdataat with rawbytes modifier is not supported.

  • Norm and raw modifiers are not supported in urilen.

  • Snort rules cannot be created on ASN1 decoded content.

  • If the length of the content or uricontent (token length) is more than 96 bytes and less than or equal to 256 bytes, the target device type is automatically set to NS-series.

  • The following PCRE constructs are not supported:

    • Lookahead and lookbehind assertions.

    • Backreferences and capturing subexpressions.

      alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"WEB-CLIENT Adobe Acrobat getCosObj file overwrite
       attempt"; flow:established,to_client; flowbits:isset,http.pdf; file_data; content:".write|28|"; nocase; 
      content:".getCosObj|28|"; distance:0; nocase; pcre:"/([A-Z\d_]+)\.write\x28.*?\1\.getCosObj\x28/smi"; reference:
      cve,2011-2442; reference:url,www.adobe.com/support/security/bulletins/apsb11-24.html; classtype:attempted-user; 
      sid:20156; rev:1;)

      In this example rule, \1 is the backreference.

    • Subroutine references and recursive patterns.

    • Conditional patterns.

      alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"WEB-IIS ASP.NET 2.0 cross-site scripting 
      attempt"; flow:to_server,established; content:"__LASTFOCUS="; fast_pattern:only; pcre:"/__LASTFOCUS=(?!([_a-z]\w*|)
      ([\x26\x3B]|$))/i"; reference:bugtraq,20337; reference:cve,2006-3436; reference:url,www.microsoft.com/technet/security
      /bulletin/MS06-056.mspx; classtype:attempted-user; sid:8700; rev:5;)

      In this example rule, !([_a-z]\w*|)([\x26\x3B]|$) is the conditional pattern.

    • Unicode character properties \p{xx} and \P{xx}.

    • Possessive quantifiers.

    The following are additional limitations regarding PCRE in Trellix IPS Snort:

    • In a Snort custom attack, the maximum value for repetition counter in PCRE is 256. If it exceeds this number, the error message Pattern too large is displayed.

    • Atomic grouping and possessive quantifiers are not supported.

    Note

    PCRE rules validation is included in the Custom Attack Editor. So, any rule containing invalid or unsupported PCRE options fail to import. You can find the reason in the error message. After you correct these rules, use the Test Compile feature to check if the they are valid and compatible. You can select the required attacks and select Other Actions → Test Compile.

The following constructs are not supported in Trellix IPS Snort:

  • ack

  • asn1

  • bidirectional operator

  • byte_extract

  • byte_jump

  • byte_test

  • cvs

  • dce_iface

  • dce_opnum

  • dce_stub_data

  • depth

  • distance

  • dnp3_ind

  • dnp3_obj

  • dsize

  • fast_pattern

  • flowbits

  • fragbits

  • fragoffset

  • ftpbounce

  • http_stat_msg

  • icmp_id

  • id

  • ip_proto

  • ipopts

  • isdataat

  • metadata

  • modbus_unit

  • offset

  • port / IP negation

  • rpc

  • sameip

  • seq

  • stream_size

  • tos

  • ttl

  • window

  • within

The following are not supported in Trellix IPS Snort, but an equivalent option is available in Trellix IPS:

  • Rules using ftpbounce keyword are not supported. However, the Trellix IPS signature sets provide adequate protection against FTP bounce attacks.

  • Rules to detect CVS attacks are not supported. However, Trellix IPS signature sets can protect your network against most of the CVS attacks.

  • Regarding Sensor response actions, you cannot use any post-detection rule options such as Logto, Session, or Tag. Instead, you can configure the required response action after the rule is saved in the Manager database. This is the same as how you would configure the response action for any other attack definition in Trellix IPS.

  • Preprocessor plugins are not supported.

  • Snort's multi-event logging (event queue) is not supported.

  • For event thresholding and alert suppression, you can use only the equivalent features in Trellix IPS and not the options in Snort.

Classification types

It is mandatory that you define the priority for each Snort Custom Attack. Priority is one of the parameters that the Manager uses when it categorizes a Snort Custom Attack. To specify the priority, you can either use the priority keyword directly in the rule or use a classification type in the rule. However, this classification type should either be available in the Manager or declared in a file up front. That is, the Manager must read the classification type declaration before it reads the rule that uses it.

Note

You can view the classification types that are currently available in the Manager. You can also re-submit rules for conversion with the currently available values.

Similar to macros, you can define the classification types in a .conf, .config, or .rules file and import it into the Manager.

In the .conf, .config, or .rules file, define the classification type using the syntax as shown below:

config classification:<class name>,<class description>,<default priority>

Example: config classification: brute-force,attempted brute force,1

Note the following:

  • The priority value 1 is mapped to a severity of high in Trellix IPS, 2 to medium, 3 to low, and 4 and above to informational.

  • The default priority value that you specify in a classification type can be overridden by using the priority keyword in the rule.