Skip to content
Discussion options

You must be logged in to vote

Rule after modify:

[root@so-standalone ~]# grep 2013028 /opt/so/rules/nids/suri/all.rules
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET POLICY curl User-Agent Outbound"; flow:established,to_server; http.user_agent; content:"curl/"; nocase; startswith; content: !"microsoft.com"; nocase; reference:url,www.useragentstring.com/pages/useragentstring.php; classtype:attempted-recon; sid:2013028; rev:8; metadata:created_at 2011_06_14, deprecation_reason Performance, updated_at 2024_07_02;)

Replies: 1 comment 7 replies

Comment options

You must be logged in to vote
7 replies
@sutehk-cs
Comment options

@cm-ops
Comment options

@Syngelik
Comment options

@cm-ops
Comment options

Answer selected by Syngelik
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants