cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
732
Views
0
Helpful
2
Replies

Custom Sigs for APT Detection

damonrouse
Level 1
Level 1

Hi

I'm totally new to writing any kind of custom signature, but was wondering if anyone has written any for APT detection?  Specifically I'm looking at creating sigs for certain TCP packet info containing HTML and mime type info.  Please let me know if this is possible.

Thanks

Damon

2 Replies 2

damonrouse
Level 1
Level 1

FYI...I opened a TAC case just now.

nearchib
Level 1
Level 1

Hi Damon,

What you described definitly sounds possible.

You will need to be more specific though if you want help with that issue.

Regards

Neil Archibald

IPS Signature Team

Review Cisco Networking products for a $25 gift card