Security-onion

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen

Setup

Check

test

  • cat /etc/nsm/rules/local.rules
alert icmp any any -> $HOME_NET any (msg:"ICMP test detected"; GID:1; sid:10000001; rev:001; classtype:icmp-event;)

nsm restart

  • service nsm restart