In Trellix IPS, you have the flexibility to create custom attacks in two ways:
You can create custom attacks in Trellix IPS's proprietary format. This type of custom attacks are signature-based. You can define one or more signatures per attack. Such attack definitions are called Trellix IPS Custom Attacks in this guide.
Note
The Trellix IPS Custom Attacks in the earlier releases were called User-Defined Signatures (UDS). The interfaces of the UDS Editor are now available within the Custom Attack Editor.
You can write rule-based custom attacks using Snort rules language, which is open-source. Such attack definitions are called Snort Custom Attacks in this guide.
Note
These two formats are not interchangeable. That is, you cannot convert a Trellix IPS Custom Attack to Snort Custom Attack or the other way around.
You can use Snort rules in your existing Trellix IPS setup without having to modify it in any way or install any Snort-related components. These rules could be your own or from sources such as the Snort user-community; the critical thing is that the rules should conform to the Snort syntax for you to use them in Trellix IPS.
A Snort Custom Attack is converted into Trellix IPS's format internally when you save it in the Manager server. This translation enables you to use Snort rules directly in Trellix IPS without the need for any Snort-related components.