From e0e669f27868f3ce442db9a76a7a5cbddef14dc6 Mon Sep 17 00:00:00 2001 From: BlackLight Date: Thu, 10 Feb 2011 20:23:23 +0100 Subject: [PATCH] Adding more ICMP ping hyperalert modules --- corr_rules/1-366-7.xml | 9 +++++++++ corr_rules/1-368-6.xml | 9 +++++++++ corr_rules/1-384-5.xml | 9 +++++++++ 3 files changed, 27 insertions(+) create mode 100644 corr_rules/1-366-7.xml create mode 100644 corr_rules/1-368-6.xml create mode 100644 corr_rules/1-384-5.xml diff --git a/corr_rules/1-366-7.xml b/corr_rules/1-366-7.xml new file mode 100644 index 0000000..cfff17f --- /dev/null +++ b/corr_rules/1-366-7.xml @@ -0,0 +1,9 @@ + + + + + 1.366.7 + ICMP PING *NIX + HostExists(+DST_ADDR+) + + diff --git a/corr_rules/1-368-6.xml b/corr_rules/1-368-6.xml new file mode 100644 index 0000000..c7419a3 --- /dev/null +++ b/corr_rules/1-368-6.xml @@ -0,0 +1,9 @@ + + + + + 1.368.6 + ICMP PING BSDtype + HostExists(+DST_ADDR+) + + diff --git a/corr_rules/1-384-5.xml b/corr_rules/1-384-5.xml new file mode 100644 index 0000000..f244922 --- /dev/null +++ b/corr_rules/1-384-5.xml @@ -0,0 +1,9 @@ + + + + + 1.384.5 + ICMP PING + HostExists(+DST_ADDR+) + +