Security-onion: Unterschied zwischen den Versionen
Zur Navigation springen
Zur Suche springen
Thomas (Diskussion | Beiträge) (→Setup) |
Thomas (Diskussion | Beiträge) |
||
| Zeile 3: | Zeile 3: | ||
=Check= | =Check= | ||
*[[Security Onion Check]] | *[[Security Onion Check]] | ||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
| − | |||
=test= | =test= | ||
Version vom 11. August 2016, 09:18 Uhr
Setup
Check
test
- cat /etc/nsm/rules/local.rules
alert icmp any any -> $HOME_NET any (msg:"ICMP test detected"; GID:1; sid:10000001; rev:001; classtype:icmp-event;)
nsm restart
- service nsm restart