Created
August 29, 2017 13:45
-
-
Save shadowbq/38bb16b91f8b2287e3eefda63fe20292 to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
NetworkFlow process, process_id where NetworkFlow src_ip contains 10.250.45.0/24 | |
and NetworkFlow dst_ip equals 10.0.0.2 | |
CurrentFlow process_id where CurrentFlow local_ip contains 10.250.45.0/24 and | |
CurrentFlow remote_ip equals 10.0.0.2 |
trigger "Network src_ip contains 10.10.0.255/24 and Network dst_ip equals 10.10.0.255/24 and Network dst_port equals 10001"
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
https://git.io/v5nB6