<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Atomic TCP Signatures in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/atomic-tcp-signatures/m-p/339575#M97439</link>
    <description>&lt;P&gt;Can we use an atomic.tcp signature to trigger any event that causes a SYN packet sent to a host?  And will it fire if for example we establish a telnet session to the host? (I assure telnet first establishes a TCP session and a SYN should go out at some point).&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 09:13:05 GMT</pubDate>
    <dc:creator>khanj</dc:creator>
    <dc:date>2019-03-10T09:13:05Z</dc:date>
    <item>
      <title>Atomic TCP Signatures</title>
      <link>https://community.cisco.com/t5/network-security/atomic-tcp-signatures/m-p/339575#M97439</link>
      <description>&lt;P&gt;Can we use an atomic.tcp signature to trigger any event that causes a SYN packet sent to a host?  And will it fire if for example we establish a telnet session to the host? (I assure telnet first establishes a TCP session and a SYN should go out at some point).&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:13:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/atomic-tcp-signatures/m-p/339575#M97439</guid>
      <dc:creator>khanj</dc:creator>
      <dc:date>2019-03-10T09:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Atomic TCP Signatures</title>
      <link>https://community.cisco.com/t5/network-security/atomic-tcp-signatures/m-p/339576#M97441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want a signature that fires on any SYN packet being sent to a certain host, you can use the atomic.tcp engine.  You will need to write a signature for any packet with the SYN flag set and then use filters to filter out the alarms for the host you are concerned with.  If this is not what you are looking for, can you please clarify what you are trying to trigger on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jan 2005 15:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/atomic-tcp-signatures/m-p/339576#M97441</guid>
      <dc:creator>micballa</dc:creator>
      <dc:date>2005-01-04T15:02:04Z</dc:date>
    </item>
  </channel>
</rss>

