Advertisement
Guest User

Rules Group 1

a guest
Jul 28th, 2016
47
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.55 KB | None | 0 0
  1. #Rule ICMP1
  2. alert icmp any any -> any any \
  3. (msg:"ICMP1";itype:8;icode:9;icmp_seq:295;sid:9000050;)
  4. event_filter gen_id 1,sig_id 9000050,type both,track by_src,count 1,seconds 300
  5.  
  6. #Rule ICMP2
  7. alert icmp any any -> any any \
  8. (msg:"I'm an ICMP Echo Request";itype:8;icode:0;icmp_seq:296;dsize:150;sid:9000051;)
  9. event_filter gen_id 1,sig_id 9000051,type both,track by_src,count 1,seconds 10
  10.  
  11. #Rule UDP
  12. alert udp $HOME_NET 43869 -> $HOME_NET any \
  13. (msg:"UDP Weirdness";\
  14. content:"|43|";offset:299;depth:1;\
  15. sid:9000052;)
  16. event_filter gen_id 1,sig_id 9000052,type both,track by_src,count 1,seconds 30
  17.  
  18. #Rule T2
  19. alert tcp any any -> any 22 \
  20. (msg:"NMAP T2 detected!";fragbits:d;flags:0;\
  21. sid:9000047;)
  22. event_filter gen_id 1,sig_id 9000047,type threshold,track by_src,count 5,seconds 30
  23.  
  24. #Rule T3
  25. alert tcp any any -> any any (msg:"TCP UPSF";fragbits:!rdm;flags:UPSF;window:256;sid:9000054;)
  26. event_filter gen_id 1,sig_id 9000054,type limit,track by_dst,count 5,seconds 22
  27.  
  28. #Rule T5
  29. #T5 rule
  30. alert tcp any any -> any any (msg:"T5 filter triggered!";flags:S;fragbits:!rdm;window:31337;sid:9000030;)
  31. event_filter gen_id 1, sig_id 9000030, type limit, track by_src, count 1, seconds 30
  32.  
  33. #Rule T6
  34. alert tcp 192.168.45.1 any -> 192.168.45.128 any \
  35. (msg:"Fragbits";flags:A+;window:32768;sid:9000057;)
  36. event_filter gen_id 1,sig_id 9000057,type both,track by_src,count 1,seconds 20
  37.  
  38. #Rule T7
  39. alert tcp any 43821 -> any 1024: \
  40. (msg:"NMAP T7 detected!";flags:FPU;\
  41. sid:9000041;)
  42. event_filter gen_id 1,sig_id 9000041,type both,track by_src,count 8,seconds 30
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement