cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1680
Views
0
Helpful
1
Replies

fmc create snort rule

yunsh63
Level 1
Level 1

Hi. 

 

I have a question about fmc create snort rule.

 

alert tcp any any -> any any (msg:"F-SCN-WEB-181102-wpscan_attempt"; flow:established, to_server; content:"User-Agent|3a 20|WPScan"; nocase; http_header; fast_pattern:only; metadata:service http; reference:url, github.com/wpscanteam/wpscan; classtype:webscan; sid:1101026; rev:1;)

 

I want about this snort rule, How can I setting the options?

 

Please help me...

1 Reply 1

phil.hydea
Level 1
Level 1
Hi,

I don't quite understand your queston. Do you need to know how to import it?

Put it into a txt file - upload it (Updates > Rule Updates>. Once uploaded, enable it into the desired rule start in your Intrusion policy.

Thanks
Review Cisco Networking for a $25 gift card