Trellix IPS policies define what hardware and software platforms are present on a network and what should be monitored. The platforms can be as generic as the HTTP protocol or as specific as Microsoft Internet Explorer running on Windows Server 2016.
After a policy is configured and saved, the Manager searches through the database and generates a list of attacks that will be enabled when that policy is applied to an interface. Attacks specify what platforms they affect as part of their impact construct.
In case of Trellix IPS Custom Attacks, the impact construct of an attack can contain references to protocols, and the packages that provide support for those protocols. Protocol references refer to protocols defined by Trellix as well as the custom-defined ones. Package references refer to particular software or hardware platforms, which can include a specific OS.
The platforms that can be selected are those for which Trellix IPS has specific support in some form. If you do not see a particular platform, you can choose the one which is similar, or specify tcpip-machine as the package, or specify just the impact protocol for the attack.
For Snort Custom Attacks, you cannot choose an impact package. By default, tcpip-machine is selected as the package, and this cannot be modified. Additionally, the Manager identifies the impact protocol for the attack definition.