Merged
Conversation
Added Range for MHN -> Cowrie and Dionaea Honeypots.
Added decoder for MHN -> Dionaea and Cowrie Honeypots.
Added rules for Cowrie honeypot in Modern Honeypot Network.
Added rules for Dionaea honeypot in Modern Honeypot Network.
Contributor
|
The regexp are IPv4 centric. Can you make them IPv6 friendly?
Tony
… On Nov 16, 2018, at 02:47, Bob-Andrews ***@***.***> wrote:
Added Range, Rules and Decoder for Cowrie and Dionaea in Modern Honeypot Network.
Did not add the mhn-json.log to the ossec.conf. Added a hint to the rule files and decoder instead.
Not sure if this rules are to special for including it directly.
You can view, comment on, or merge this pull request online at:
#1574
Commit Summary
Added Range for MHN
Added decoder for MHN
Added MHN Cowrie Rules
Added rules for MHN Dionaea
Corrected mhn range order
File Changes
M doc/rule_ids.txt (2)
M etc/decoder.xml (40)
A etc/rules/mhn_cowrie_rules.xml (26)
A etc/rules/mhn_dionaea_rules.xml (13)
Patch Links:
https://github.com/ossec/ossec-hids/pull/1574.patch
https://github.com/ossec/ossec-hids/pull/1574.diff
—
You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub, or mute the thread.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Added Range, Rules and Decoder for Cowrie and Dionaea in Modern Honeypot Network.
Did not add the mhn-json.log to the ossec.conf. Added a hint to the rule files and decoder instead.
Not sure if this rules are to special for including it directly.