2016年9月30日 星期五

snort local rule

you can write your own rule for testing snort, or to detect specific pattern you desire. a simple icmp sample as below. sid is needed for newer version.

alert icmp any any -> any any (msg: "ICMP traffic"; sid:001;)

沒有留言:

張貼留言