After you save the custom attacks in the Manager server, verify if the attacks in Published State have actually been published in the policies. The attacks are categorized based on the following and then published in the corresponding rule sets.
When you have finished creating a custom attack, you need to save it. Saving the attack in the Manager server, publishes your attack definition in every rule set where your attack fits one or more categories, provided the State of the attack is Published. When you apply a policy that publishes a rule set containing your attack, detection of your attack is active.
The Manager categorizes attacks based on:
Impact application
Impact operating system
Impact application layer protocol
Severity of the attack
Benign Trigger Probability (BTP)
For example, when you created a Trellix IPS Custom Attack, you set the Severity to Medium and chose HTTP as the Exploit classification. Once saved in the Manager server, the attack is published in all rule sets that include Medium-severity, HTTP attacks, such as the Default, Outside Firewall, and Web Server rule sets provided with Trellix IPS. (This also publishes any rule set that you have created which calls for HTTP attacks of Medium severity or higher.) When you apply a policy that publishes one of these rule sets to a port or VIDS, you are publishing your attack for IPS.
Note
If you make a name change to either the attack or a signature within the attack, then save it back into the Manager, the name change will not take affect in any open Attack Log views. You must close all Attack Log windows and restart the Attack Log to see the name change upon attack detection.