Florian Roth
789b3899df
Improved Linux Shell Activity Rule
2017-03-15 09:07:59 +01:00
Florian Roth
9afa12f4a3
Further shell commands from MSF repo
2017-03-14 16:33:51 +01:00
Florian Roth
daeb7c3693
Rule: Suspicious activity in shell commands
2017-03-14 14:54:08 +01:00
Florian Roth
546a587df7
Rule: Shellshock Regex detection
...
http://rubular.com/r/zxBfjWfFYs
2017-03-14 14:53:29 +01:00
Florian Roth
3eae1f2710
Bug and typo fixes
2017-03-14 14:52:28 +01:00
Florian Roth
9934a66a3c
Rule: ClamAV
2017-03-01 10:00:17 +01:00
Florian Roth
2e0632b05f
Rule: Linux: buffer overflows
2017-03-01 08:38:33 +01:00
Florian Roth
001bed0c45
ModSecurity rule: multiple blocks
2017-02-28 17:53:32 +01:00
Florian Roth
b1446f9b87
Removed 'last' keyword from 'timeframe' fields
2017-02-28 17:52:40 +01:00
Florian Roth
18fd63f6b7
Levels to low, medium, high, critical
2017-02-16 18:06:22 +01:00
Thomas Patzke
88270fcf2d
Rule review and cleanup
...
* removed unnecessary one element lists from definitions
* converted some lists of one element maps to maps because the resulting
OR linkage would cause wrong result.
2017-02-15 23:53:08 +01:00
Florian Roth
a2adb1ddb5
Renamed rule files, new rules
2017-02-10 19:17:02 +01:00
Florian Roth
1307a45fd5
Moved rules to a separate directory
2017-02-07 00:44:40 +01:00