zeek/scripts/s2b/etc/s2b-ruleset-augment.cfg

157 lines
2 KiB
INI

<attack-responses.rules>
</attack-responses.rules>
<backdoor.rules>
</backdoor.rules>
<bad-traffic.rules>
</bad-traffic.rules>
<chat.rules>
</chat.rules>
<ddos.rules>
</ddos.rules>
<deleted.rules>
</deleted.rules>
<dns.rules>
</dns.rules>
<dos.rules>
</dos.rules>
<experimental.rules>
</experimental.rules>
<exploit.rules>
</exploit.rules>
<finger.rules>
</finger.rules>
<ftp.rules>
requires-reverse-signature ! ftp_server_error
</ftp.rules>
<icmp.rules>
</icmp.rules>
<imap.rules>
</imap.rules>
<info.rules>
</info.rules>
<local.rules>
</local.rules>
<misc.rules>
</misc.rules>
<multimedia.rules>
</multimedia.rules>
<mysql.rules>
</mysql.rules>
<netbios.notes>
</netbios.notes>
<netbios.rules>
</netbios.rules>
<nntp.rules>
</nntp.rules>
<oracle.rules>
</oracle.rules>
<other-ids.rules>
</other-ids.rules>
<p2p.rules>
</p2p.rules>
<policy.rules>
</policy.rules>
<pop2.rules>
requires-reverse-signature ! pop_return_error
</pop2.rules>
<pop3.rules>
requires-reverse-signature ! pop_return_error
</pop3.rules>
<porn.rules>
</porn.rules>
<rpc.rules>
</rpc.rules>
<rservices.rules>
</rservices.rules>
<scan.rules>
</scan.rules>
<shellcode.rules>
</shellcode.rules>
<smtp.rules>
requires-reverse-signature ! smtp_server_fail
</smtp.rules>
<snmp.rules>
</snmp.rules>
<sql.rules>
</sql.rules>
<telnet.rules>
</telnet.rules>
<tftp.rules>
</tftp.rules>
<virus.rules>
</virus.rules>
<web-attacks.rules>
requires-reverse-signature ! http_error
</web-attacks.rules>
<web-cgi.rules>
requires-reverse-signature ! http_error
</web-cgi.rules>
<web-client.rules>
</web-client.rules>
<web-coldfusion.rules>
requires-reverse-signature ! http_error
</web-coldfusion.rules>
<web-frontpage.rules>
requires-reverse-signature ! http_error
eval isIIS
</web-frontpage.rules>
<web-iis.rules>
requires-reverse-signature ! http_error
eval isIIS
</web-iis.rules>
<web-misc.rules>
requires-reverse-signature ! http_error
</web-misc.rules>
<web-php.rules>
requires-reverse-signature ! http_error
</web-php.rules>
<x11.rules>
</x11.rules>