Skip to content

in which file rules is defined not getting alert message  #4

@vija9751

Description

@vija9751

i want to know where i have to chane the rule
ex: alert tcp any any -> $HOME_NET 9389 (msg:"SS POLICY Active Directory Web Services"; flow:to_server,established; flags:PA; content:"/ActiveDirectoryWebServices/Windows/Enumeration"; classtype:attempted-recon; sid:1000001;) where i have to write exactly

alert tcp any any -> any any (msg:"Feature1"; content:"#JN1"; nocase;

how to get this

05/-22:56:55.056993 [] [1:2019:0] Feature1 [] [Priority: 0] {TCP}
46.20.153.125:80 -> 10.0.2.15:56216

how to get message of Feature1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions