Skip to content
Discussion options

You must be logged in to vote
  1. That SID has flowbits set. You would need to modify the rule, not disable it, using something like this:

2034812 “flowbits:set,ET.LDAPBindRequest;” “flowbits:set,ET.LDAPBindRequest; flowbits:noalert;”'

  1. Yes, ET OPEN ships with many rules disabled by default; if there's something disabled that you would like to enable, you can do that through the idstools configuration interface.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by ByteAndBits
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants