diff --git a/corr_rules/1-366-7.xml b/corr_rules/1-366-7.xml new file mode 100644 index 0000000..cfff17f --- /dev/null +++ b/corr_rules/1-366-7.xml @@ -0,0 +1,9 @@ + + + + + 1.366.7 + ICMP PING *NIX + HostExists(+DST_ADDR+) + + diff --git a/corr_rules/1-368-6.xml b/corr_rules/1-368-6.xml new file mode 100644 index 0000000..c7419a3 --- /dev/null +++ b/corr_rules/1-368-6.xml @@ -0,0 +1,9 @@ + + + + + 1.368.6 + ICMP PING BSDtype + HostExists(+DST_ADDR+) + + diff --git a/corr_rules/1-384-5.xml b/corr_rules/1-384-5.xml new file mode 100644 index 0000000..f244922 --- /dev/null +++ b/corr_rules/1-384-5.xml @@ -0,0 +1,9 @@ + + + + + 1.384.5 + ICMP PING + HostExists(+DST_ADDR+) + +