The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Verify the inclusion of custom attack in IPS policies

Prev Next

Steps to verify if a custom attack has been published in a rule set:

  1. Select Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS.

  2. Double-click the "Default Testing " attack set to view the selected attacks.

    GUID-DD09CE59-FFE2-45A2-A214-2D20F68A669B-low.png
  3. Scroll down the list (sorted alphabetically) to find your attack file.

    Trellix IPS Custom Attacks have "UDS-" appended to the beginning of the name, while Snort Custom Attacks have "SNORT-" appended to the beginning.

    GUID-1300AE9E-93D6-4652-BC0F-41626BD5EC88-low.png