Rules contain both required and optional sections, one section per line. Each section defines a rule category and its value. One section always identifies the class of the rule, which defines the rule’s overall behavior. Optional sections vary according to the class of the rule.
Note
Exploit Prevention is not supported in the ARM architecture.
Here is the basic structure of a McAfee Host IPS rule:
Rule {
SectionA value
SectionB value
SectionC value
...
}Because the structure and class types for legacy Expert Rules are identical to those in McAfee Host IPS, you can copy existing McAfee Host IPS rules into Trellix ENS Expert Rules.
Note
Trellix ENS doesn't support signatures with multiple rules.