Skip to content

in which file rules is defined not getting alert message  #4

Description

@vija9751

i want to know where i have to chane the rule
ex: alert tcp any any -> $HOME_NET 9389 (msg:"SS POLICY Active Directory Web Services"; flow:to_server,established; flags:PA; content:"/ActiveDirectoryWebServices/Windows/Enumeration"; classtype:attempted-recon; sid:1000001;) where i have to write exactly

alert tcp any any -> any any (msg:"Feature1"; content:"#JN1"; nocase;

how to get this

05/-22:56:55.056993 [] [1:2019:0] Feature1 [] [Priority: 0] {TCP}
46.20.153.125:80 -> 10.0.2.15:56216

how to get message of Feature1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions