snort2-docker/docker/labs/lab2/local.rules

2 lines
222 B
Plaintext
Raw Normal View History

2020-02-24 13:56:30 +00:00
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"TEST Curl outbound connection attempt"; flow:to_server,established; content:"User-Agent: "; http_header; content:"curl/"; http_header; fast_pattern; sid:1000000;)