cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
452
Views
0
Helpful
3
Replies

IDS Signature List Export Table

dbarry
Level 1
Level 1

Does anybody have a list of all the IDS signatures in an exportable format? I'm looking for a table that has the Signature/SubID, Alarm Level, Signature Type, Signature Structure, Implementation, and description.

With that it would be easy to create txt config files for setting the Signature responses (and without all the WWW-clicking).

The Secure Encyclopedia doesn't have the list in a downloadable format.

3 Replies 3

msmitha
Level 1
Level 1

Not exactly what you could be looking for but I use this:

http://www.cisco.com/cgi-bin/front.x/csec/idsHome.pl

I've seen that. But what I'm looking for would be a text document (or spreadsheet) of the information.

From that, I can build a config file to set all the alerts we want for all the signatures, and easily apply it to other cisco IDS boxes, as well as the one we'll test on our next DRP drill!

Are you running version 4.x?

If so then try the following:

configure terminal

service virtual-sensor-configuration virtualSensor

tune-micro-engines

show settings | include SIGID|SubSig|AlarmSeverity|EventAction|SigName|Enabled

You could then add any other fields by adding another "|" followed by the field name.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: