The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update Attack Set Profile Configuration Detail

Prev Next

This URL updates the attack set profile configuration details at domain level.

Resource URL

PUT /domain/<domainId>/ attacksetprofile/updateruleset/<policyId>

Request Parameters

URL Parameters:

Field Name Description Data Type Mandatory
domainId Domain id Number Yes
policyId Policy id Number Yes

Payload parameters:

Field Name Description Data Type Mandatory
policyName Policy name String Yes
description Policy description String Yes
enableRfSBExpoit RfSB exploit configuration Boolean Yes
enableRfSBMalware RfSB malware configuration Boolean Yes
enableRfSBRecon RfSB recon configuration Boolean Yes
enableRfSBPolicy RfSB policy configuration Boolean Yes
isEditable AttackSet editable configuration Boolean No
action Inclusion/exclusion of rules Values can be:
  • INCLUDE
  • EXCLUDE
String No
comment Comments String No
isSpecificAttack Specific attack name Boolean No
AttackList List of attacks String No
minSeverity Severity level values can be:
  • NONE
  • HIGH_9
  • HIGH_8
  • HIGH_7
  • MEDIUM_6
  • MEDIUM_5
  • MEDIUM_4
  • LOW_3
  • LOW_2
  • LOW_1
  • INFORMATIONAL_0
String No
maxBTP BTP level values can be:
  • NONE
  • HIGH_7
  • HIGH_6
  • MEDIUM_5
  • MEDIUM_4
  • MEDIUM_3
  • LOW_2
  • LOW_1
String No
attackType Type of attack values can be:
  • ANY
  • RF_SB_ONLY
String No
attackCategory Attack category String No
Application Application list String No
Protocol Protocols String No
operatingsystem Operating system String No

Response Parameters

Following fields are returned if the operation was successful, otherwise error details are returned.

Field Name Description Data Type
status Set to 1 if the operation was successful Number

Example

Request

PUT https://<NSM_IP>/sdkapi/domain/<domainId>/attacksetprofile/updateruleset/<policyId>

Payload

{"policyName":"API new create2",
"description":"Include all except for the RECONNAISSANCE\ncategory, and excluding known noisy signatures.",
"enableRfSBExpoit":false,
"enableRfSBMalware":false,
"enableRfSBRecon":false,
"enableRfSBPolicy":false,
"rules":[{"action":"INCLUDE",
"comment":null,"isSpecificAttack":false,"AttackList":[],"minSeverity":"LOW(2)","maxBTP":"MEDIUM(4)","attackType":"ANY","attackCategory":[null],"application":[null],"protocol":[null],"operatingsystem":[null]}]} 

Response

{
status:1
           } 
 

Error Information

Following error codes are returned by this URL:

No SDK API errorId SDK API errorMessage
1 1105 Invalid domain
2 7001 Invalid policy id
3 7001 Duplicate name detected
4 7001 The first rule in the list must be an Include rule
5 7001 Invalid attack type input
6 7001 A rule cannot contain multiple items of multiple categories at the same time