The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Update Attack Set Profile Configuration Detail

Prev Next

This URL updates the attack set profile configuration details at domain level.

Resource URL

PUT /domain/<domainId>/ attacksetprofile/updateruleset/<policyId>

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domainId

Domain id

Number

Yes

policyId

Policy id

Number

Yes

Payload parameters:

Field Name

Description

Data Type

Mandatory

policyName

Policy name

String

Yes

description

Policy description

String

Yes

enableRfSBExpoit

RfSB exploit configuration

Boolean

Yes

enableRfSBMalware

RfSB malware configuration

Boolean

Yes

enableRfSBRecon

RfSB recon configuration

Boolean

Yes

enableRfSBPolicy

RfSB policy configuration

Boolean

Yes

isEditable

AttackSet editable configuration

Boolean

No

action

Inclusion/exclusion of rules Values can be:

  • INCLUDE

  • EXCLUDE

String

No

comment

Comments

String

No

isSpecificAttack

Specific attack name

Boolean

No

AttackList

List of attacks

String

No

minSeverity

Severity level values can be:

  • NONE

  • HIGH_9

  • HIGH_8

  • HIGH_7

  • MEDIUM_6

  • MEDIUM_5

  • MEDIUM_4

  • LOW_3

  • LOW_2

  • LOW_1

  • INFORMATIONAL_0

String

No

maxBTP

BTP level values can be:

  • NONE

  • HIGH_7

  • HIGH_6

  • MEDIUM_5

  • MEDIUM_4

  • MEDIUM_3

  • LOW_2

  • LOW_1

String

No

attackType

Type of attack values can be:

  • ANY

  • RF_SB_ONLY

String

No

attackCategory

Attack category

String

No

Application

Application list

String

No

Protocol

Protocols

String

No

operatingsystem

Operating system

String

No

Response Parameters

Following fields are returned if the operation was successful, otherwise error details are returned.

Field Name

Description

Data Type

status

Set to 1 if the operation was successful

Number

Example

Request

PUT https://<NSM_IP>/sdkapi/domain/<domainId>/attacksetprofile/updateruleset/<policyId>

Payload

{"policyName":"API new create2",
"description":"Include all except for the RECONNAISSANCE\ncategory, and excluding known noisy signatures.",
"enableRfSBExpoit":false,
"enableRfSBMalware":false,
"enableRfSBRecon":false,
"enableRfSBPolicy":false,
"rules":[{"action":"INCLUDE",
"comment":null,"isSpecificAttack":false,"AttackList":[],"minSeverity":"LOW(2)","maxBTP":"MEDIUM(4)","attackType":"ANY","attackCategory":[null],"application":[null],"protocol":[null],"operatingsystem":[null]}]}

Response

{
status:1
           } 

Error Information

Following error codes are returned by this URL:

No

SDK API errorId

SDK API errorMessage

1

1105

Invalid domain

2

7001

Invalid policy id

3

7001

Duplicate name detected

4

7001

The first rule in the list must be an Include rule

5

7001

Invalid attack type input

6

7001

A rule cannot contain multiple items of multiple categories at the same time