summaryrefslogtreecommitdiffstats
path: root/clover/cloverctl/src/cloverctl/yaml/idsrule_scan.yaml
diff options
context:
space:
mode:
authorStephen Wong <stephen.kf.wong@gmail.com>2018-08-19 07:18:00 +0000
committerGerrit Code Review <gerrit@opnfv.org>2018-08-19 07:18:00 +0000
commit94cd16d7b0dc898e0c54ebe0f8378f27ded67e14 (patch)
treead7df714704a6bccb0b46b874062ef9cf6f1377b /clover/cloverctl/src/cloverctl/yaml/idsrule_scan.yaml
parentd24dce594859ece995e2775013951a3e12258d95 (diff)
parentc0837d0701009e6142f9800f2b146bec17d6910f (diff)
Merge "Implement initial cloverctl CLI tool"
Diffstat (limited to 'clover/cloverctl/src/cloverctl/yaml/idsrule_scan.yaml')
-rw-r--r--clover/cloverctl/src/cloverctl/yaml/idsrule_scan.yaml9
1 files changed, 9 insertions, 0 deletions
diff --git a/clover/cloverctl/src/cloverctl/yaml/idsrule_scan.yaml b/clover/cloverctl/src/cloverctl/yaml/idsrule_scan.yaml
new file mode 100644
index 0000000..1cce7f7
--- /dev/null
+++ b/clover/cloverctl/src/cloverctl/yaml/idsrule_scan.yaml
@@ -0,0 +1,9 @@
+sid: "10000003"
+protocol: tcp
+dest_port: any
+dest_ip: $HOME_NET
+src_port: any
+src_ip: any
+msg: MALWARE-CNC User-Agent ASafaWeb Scan
+rev: "001"
+content: '"asafaweb.com"'