The rule set is organized into categories, and the console exposes them as a checklist. Malware, botnet command-and-control, exploit and exploit-kit activity, network trojans, scanning, denial of service, web application attack, shellcode, attack response, information leak, peer-to-peer, adware and potentially unwanted programs, policy, and informational families each map to a slice of the Emerging Threats catalog.
The sensitivity level is a preset over that checklist. Moving between the named levels changes how many categories are enabled, from a narrow selection weighted toward high-severity, high-confidence signatures to a broad selection that also carries policy and informational rules.
Here is the step worth doing rather than reading about: pick a level, then switch the selector to the custom option and look at which boxes it actually checked. The label matters far less than the resulting category list, and that list is what determines both your alert volume and your CPU load.
The categories sort into roughly three tiers of operational value. Malware, botnet C2, exploit, trojan, and attack-response rules are high-signal and worth running in prevention mode on almost any network.
Scan, denial-of-service, and web-application rules sit in the middle. They fire constantly on any public IP address, and most of what they report is internet background radiation rather than a targeted campaign.
Policy, informational, peer-to-peer, and games categories are where false positives live. These rules flag ordinary behavior: a torrent client, a vendor telemetry beacon, a remote-support tool, a game console negotiating NAT traversal.
That said, they are not useless. On a network where torrenting or unmanaged remote access violates policy, those categories are precisely the control you want, provided you are willing to read the log they generate.
One structural detail matters when you plan this out. UniFi applies a single mode across the whole enabled rule set, so a category you cannot afford to have dropped is a category you either leave unchecked or handle with a targeted signature suppression.
Overall, the workable default on a mixed network is a tight selection of high-signal categories in prevention mode, with the noisy families added deliberately and only where someone will actually act on the alerts.