This blog is mainly my brain dump. I use it as a cookbook for Linux-Unix-Security stuff.
Tuesday, October 11, 2011
Here are some search tips for sguil IDS alerts search
- Search for all event that have a destination IP of 192.168.99.1
- Search for a specific Snort SID
- Search for an event ID (650: SHELLCODE x86 setuid 0) with a destination IP of 192.168.99.1
Subscribe to:
Comments (Atom)