diff --git a/corr_rules/1-1924-8.xml b/corr_rules/1-1924-8.xml new file mode 100644 index 0000000..3963b99 --- /dev/null +++ b/corr_rules/1-1924-8.xml @@ -0,0 +1,14 @@ + + + + + 1.1924.8 + RPC mountd UDP export request + + HostExists(+DST_ADDR+) + HasService(+DST_ADDR+, +DST_PORT+) + HasRemoteAccess(+SRC_ADDR+, +DST_ADDR+) + + HasNfsAccess(+SRC_ADDR+, +DST_ADDR+) + + diff --git a/corr_rules/1-579-10.xml b/corr_rules/1-579-10.xml new file mode 100644 index 0000000..186bd6a --- /dev/null +++ b/corr_rules/1-579-10.xml @@ -0,0 +1,14 @@ + + + + + 1.579.10 + RPC portmap mountd request UDP + + HostExists(+DST_ADDR+) + HasService(+DST_ADDR+, +DST_PORT+) + HasRemoteAccess(+SRC_ADDR+, +DST_ADDR+) + + HasNfsAccess(+SRC_ADDR+, +DST_ADDR+) + +
HostExists(+DST_ADDR+)
HasService(+DST_ADDR+, +DST_PORT+)
HasRemoteAccess(+SRC_ADDR+, +DST_ADDR+)