The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Use case scenarios

Prev Next

This section describes the following user scenarios:

  • Select the Suricata Snort engine and import the Snort rules.

  • Create an attack by using String Pattern Match to detect a specific string in the HTTP GET requests.

  • Create an attack by using Numeric Pattern Match to detect a specific numeric value in the FTP protocol.

  • Create an attack by using Numeric Range Match to detect if the ports are in the specified range in the signature for HTTP protocol.

  • Create an attack by using Numeric Enumeration Match to detect if the response code matches the ones specified in the signature for HTTP protocol.

  • Create an attack by using Single Fixed Field Match to detect if the IP address and the protocol matches the ones specified in the signature.

  • Create an attack by using Packet Grep Protocol to detect if the packets contain a specific string sequence.

To open the Custom Attack Editor, select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS. Click Custom Attacks.