cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
223
Views
0
Helpful
1
Replies

custom signature

fengluo
Level 1
Level 1

I am trying to write my custom signature. I know Cisco has signature engine, but for me, it's complicated, is there a easy way to write my own signature? For example, I want to have a signature to tell me who logged in the ftp server anonymously.

1 Reply 1

rzcisco
Level 1
Level 1

you should verify 3 points ,

- you want to create a string signiture .

- you want to create a connection based signiture .

- you want to costumize exsiting general signitures .

now ,

if u want to create string based signiture you can do as follow :

on cspm or likewise cisco works vms :

- go to sensor signiture menu.

- go to your active signiture template.

- go to signitures menu.

- go to string signiture menu.

- click add .

- enter the strign name .( ie . i wanna monitor all user which enter the word xxx in their IE sessions ; i enter here "xxx" as string .

- specify port .( here 80 ,you may know 80 is http ;) )

-direction : to and from .

- enable

- action : IP LOG ,or block or what e

-ok

-continue

- save

- update

- command /approve

- ok ok

now test it somehow .

-----------------------------------------------------------

u wanna create a connection based :

go to connection signiture this beside and add u'r interest simply.

-----------------------------------------------------------

if u wanna do more professional manipulation u should go to sensor :

/user/nrg/

bye

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: