<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: help me build a custom sig in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-me-build-a-custom-sig/m-p/648785#M92407</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could just create a string TCP signature similar to 3130-0 that only looks for the filename (on ports 21,25,80).  You can 'clone' button to copy an existing sig. That would be pretty generic and may be prone to false positives though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also create 3 signatures that are more specific to the protocols you want to inspect (SMTP,HTTP,FTP).  Take a look at 3110-0 for how you would do this with the SMTP state engine. See 5326-0 for an HTTP engine example (this detects GET requests only though, not files returned from a POST request).  The 3110 example above should work for FTP (port 21).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Sep 2006 18:46:47 GMT</pubDate>
    <dc:creator>mhellman</dc:creator>
    <dc:date>2006-09-19T18:46:47Z</dc:date>
    <item>
      <title>help me build a custom sig</title>
      <link>https://community.cisco.com/t5/network-security/help-me-build-a-custom-sig/m-p/648783#M92403</link>
      <description>&lt;P&gt;Can I build a signature (and if so can you walk me through how) to alert me of any traffic containing "filename.exe"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So that for example if an email was on its way to our mailserver with such a file attached or a user was downloading such a file via FTP or through a link in a web page, I could reset the connection or at least generate an alert indicating the activity was taking place?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-me-build-a-custom-sig/m-p/648783#M92403</guid>
      <dc:creator>slug420</dc:creator>
      <dc:date>2019-03-10T10:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: help me build a custom sig</title>
      <link>https://community.cisco.com/t5/network-security/help-me-build-a-custom-sig/m-p/648784#M92404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The documentation on creating custom signatures for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids12/cliguide/clisgdef.htm#wp1042406" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/iaabu/csids/csids12/cliguide/clisgdef.htm#wp1042406&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Sep 2006 17:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-me-build-a-custom-sig/m-p/648784#M92404</guid>
      <dc:creator>a-vazquez</dc:creator>
      <dc:date>2006-09-19T17:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: help me build a custom sig</title>
      <link>https://community.cisco.com/t5/network-security/help-me-build-a-custom-sig/m-p/648785#M92407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could just create a string TCP signature similar to 3130-0 that only looks for the filename (on ports 21,25,80).  You can 'clone' button to copy an existing sig. That would be pretty generic and may be prone to false positives though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also create 3 signatures that are more specific to the protocols you want to inspect (SMTP,HTTP,FTP).  Take a look at 3110-0 for how you would do this with the SMTP state engine. See 5326-0 for an HTTP engine example (this detects GET requests only though, not files returned from a POST request).  The 3110 example above should work for FTP (port 21).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Sep 2006 18:46:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-me-build-a-custom-sig/m-p/648785#M92407</guid>
      <dc:creator>mhellman</dc:creator>
      <dc:date>2006-09-19T18:46:47Z</dc:date>
    </item>
  </channel>
</rss>

