ISS Proventia Inline Appliance Policy
[ issPolicy v1.01 | http://packet.sequenced.org/projects/isspolicy ]



POLICY INFORMATION

   Policy File: policies/AttackBlocker_inline.policy
   Policy Name: Attack Blocker
   Policy Version: 8.0.2004.286
   Sensor Type: Proventia Inline Appliance (v8.0)


SIGNATURES POLICY

Response Summary Legend: DISPLAY | LOGDB | EMAIL | SNMP | RSKILL | OPSEC | LOGEVIDENCE | DROP | DYNAMICBLOCK

Signature NameSignature DescriptionSignature StatusSignature PriorityResponse SummaryLogDropDynamicBlock
6in4_TunnelAn IPv6 over IPv4 6in4 tunnel has been detectedDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AIX_Pdnsd_OverflowAIX pdnsd buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AOLIM_AddExternalApp_OverflowAOL Instant Messenger AddExternalApp OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AOLIM_File_XferAOL Instant Messenger file transferDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AOLIM_GameRequest_OverflowAOL Instant Messenger game request overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AOLIM_LoginAOL Instant Messenger loginDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AOLIM_MessageAOL Instant Messenger messageDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AOLIM_Password_ChangeAOL Instant Messenger password changeDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AOLIM_Trillian_Encrypt_HandshakeTrillian encrypted messaging handshakeDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AOL_Instant_Messenger_OverflowAOL Instant Messenger overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
ASP_Chunked_OverflowIIS ASP Chunked Encoding OverflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
AUDIT_DNS_Version_RequestBind Version Information RequestedDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Allaire_JRun_JSP_ExecuteAllaire JRun JSP executionEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Allaire_JRun_SSIFilterAllaire JRun SSIFilter servletEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Allaire_JRun_Sample_FilesAllaire JRun sample filesEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Allaire_JRun_WebInf_DotSlashAllaire JRun WEB-INF /./ exploitEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Allaire_JRun_WebInf_SlashSlashAllaire JRun WEB-INF double slash allows remote file accessEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Alvgus_RequestAlvgus BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Alvgus_ResponseAlvgus BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Alvgus_TCP_RequestAlvgus BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Alvgus_TCP_ResponseAlvgus BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Amanda_TCP_ResponseAmanda trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AntiSniff_ARP_TestAnti-Sniff ARP packet test detectionEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AntiSniff_DNS_TestAnti-Sniff DNS packet test detectionEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
AolAdmin_ResponseAolAdmin BackdoorEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
Ascend_KillAscend kill denial of service attackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Ascend_Kill_IIAscend AttackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Asylum_ResponseAsylum BackdoorEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
Audit_TFTP_Get_FilenameTFTP Get FilenameDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Avaya_Cajun_Default_SNMPAvaya SNMP agent back door community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BDDT_TCP_ResponseBDDT trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BGP_Illegal_SizeIllegal size BGP message or parameterEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BGP_New_RouteBGP new route advertisementDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BGP_Notify_MsgBGP notification messageDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BGP_Route_UnreachableBGP route has become unreachableDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BOOTP_Remote_OverflowBOOTP File OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackConstruction_ResponseBackConstruction backdoorEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
BackDoor_TCP_ResponseBackDoor trojan horse activityEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
BackOrifice2K_TCP_Auth_RequestBack Orifice 2000 pingEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackOrifice2K_TCP_Auth_ResponseBack Orifice 2000 authEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackOrifice2K_TCP_RequestBack Orifice 2000 commandEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackOrifice2K_TCP_ResponseBack Orifice 2000 responseEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackOrifice2K_UDP_Auth_RequestBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackOrifice2K_UDP_Auth_ResponseBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackOrifice2K_UDP_RequestBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackOrifice2K_UDP_ResponseBackOrifice 2000 command decodesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackOrifice_PingBack Orifice pingEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackOrifice_RequestBack Orifice scanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BackOrifice_ResponseBack Orifice responseEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
Backage_TCP_RequestBackage BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Balistix_RequestBalistix BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Balistix_ResponseBalistix BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BasicHell_TCP_ResponseBasic Hell trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Beast_TCP_ResponseBeast trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BigGluck_ResponseBigGluck BackdoorEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
Bigorna_TCP_ResponseBigorna trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BioNet_ResponseBionet trojan horse activityEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
BitTorrent_Get_RequestBitTorrent Get Request DetectedDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BitTorrent_ResponseBitTorrent peer-to-peer activityDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Bla_RequestBla BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BlackAngel_TCP_ResponseBlack Angel trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BladeRunner_TCP_RequestBladeRunner trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BladeRunner_TCP_ResponseBladeRunner trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Blazer5_ResponseBlazer5 BackdoorEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
BloodFestEvolution_TCP_ResponseBlood Fest Evolution trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
BoinkBoink DoSEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
BonkBonk DoSEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
Bootparamrpc.bootparam whoami mismatchEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Bugs_ResponseBugs BackdoorEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
Buschtrommel_TCP_ResponseBuschtrommel trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Buttman_TCP_RequestButtman trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Buttman_TCP_ResponseButtman trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CVS_Argumentx_Double_FreeCVS Argumentx Double FreeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CVS_Auth_User_FailureCVS user login failedDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CVS_Auth_User_SuccessCVS user login success detectedDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CVS_Directory_Double_FreeCVS Directory Request Double FreeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CVS_Notify_UnderflowCVS Notify UnderflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CVS_Request_Argument_OverflowCVS Request Argument OverflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CVS_Request_EntryLine_OverflowCVS Request Entry Line OverflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CVS_Request_Option_OverflowCVS Request Option OverflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CVS_Request_Path_OverflowCVS Request Path OverflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CVS_Request_Tag_OverflowCVS Request Tag OverflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cafeini_TCP_ResponseCafeini trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Celine_TCP_ResponseCeline trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cerebus_ScannerCerebus ScanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cero_TCP_ResponseCero trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Chargen_Denial_of_ServiceChargen denial of service attackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Chupacabra_RequestChupacabra BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cisco_CR_DoSCisco Carriage Return Denial of ServiceEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cisco_Cable_Docsis_SNMP_CommunityCisco IOS cable-docsis hidden SNMP community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cisco_H323_OverflowH225.0v4 illegal length field overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cisco_ILMI_SNMP_CommunityCisco IOS "ILMI" hidden SNMP community stringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cisco_IOS_IPV4_DoSCisco IOS IPV4 DoSEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cisco_IOS_OSPF_BOCisco OSPF IOS OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cisco_IdentCisco identification port activityEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Coma_ResponseComa BackdoorEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
ConnectionBackdoor_ResponseConnection BackdoorEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
Corrupt_IP_OptionsCorrupt IP optionsEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CrackDown_TCP_ResponseCrackDown trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CrazzyNet_ResponseCrazzyNet BackdoorEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
CyberCop_Scanner_HTTPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CyberCop_Scanner_ICMPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CyberCop_Scanner_RPCCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CyberCop_Scanner_RadiusCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CyberCop_Scanner_SMTPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
CyberCop_Scanner_TFTPCyberCop Scanner decodeEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cyn_RequestCyn trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cyn_ResponseCyn trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cyn_TCP_RequestCyn trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Cyn_TCP_ResponseCyn trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DCOM_Large_Body_ExtensionCOM+ Large Body ExtensionEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DCOM_RemoteActivateDCOM/COM+ Remote Activation requestDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DCOM_RemoteGetClassObject_DoSDCOM RemoteClassObject Denial-of-ServiceEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
DCOM_Scada_Opc_BindDCOM SCADA OPC bindDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DCOM_Scada_Opc_BoDCOM SCADA OPC Buffer OverflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
DCOM_SystemActivationCOM+ ISystemActivation requestDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DFchGrisch_TCP_ResponseDFch Grisch trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DHCP_AckDHCP AckDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DHCP_DiscoverDHCP DiscoverDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DHCP_Domain_MetacharDHCP Domain MetacharEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DHCP_Format_String_BODHCP printf style Format StringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DHCP_Hostname_OverflowDHCP Hostname overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DHCP_Long_Discover_MessageDHCP Hostname overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DHCP_Minires_Format_OverflowDHCP Minires library format string overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DHCP_RequestDHCP RequestDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Address_LengthDNS Internet not 4 bytesEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Antisniff_OverflowAntiSniff DNS exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Bind_OPT_DoSDNS BIND OPT large UDP payload sizeEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Bind_SIG_OverflowDNS BIND SIG response buffer overflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
DNS_Chaos_RequestDNS Chaos lookupEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Crack_SuccessDNS crack successfulEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Excessive_RequestsExcessive DNS requestsEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Format_StringDNS name overflow contains %Enabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Generic_Intel_OverflowDNS Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_HInfoDNS HINFO queryEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Hostname_OverflowDNS name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Hostname_Overflow_VerylongDNS name overflow very longEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_IQueryDNS IQUERYEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_IQuery_boDNS I-Query exploitEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_MalformedDNS malformedEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Malformed_CompressedNameDNSEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_NULL_QueryDNS nullEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_NXT_OverflowDNS NXT record overflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
DNS_NonInternetDNS non-Internet lookupEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_PoisonDNS cache poisonEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Query_AllDNS dump All requestsDisabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Spoof_FailedDNS spoof attemptEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Spoof_SuccessDNS spoof successfulEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_TSIG_OverflowDNS TSIG name overflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
DNS_Version_RequestDNS BIND version requestEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_VirusScanTrojanDNS VirusScanTrojanEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_WINS_DoSDNS/WINS DoSEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Windows_SMTP_OverflowDNS Windows Server 2003 SMTP service overflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
DNS_Zero_Size_UDPArgent Office denial of service attackEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Zone_TransferDNS Zone transfersEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DNS_Zonexfer_HighDNS Zone Xfer from high port numberEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DRat_TCP_ResponseDRat trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DTr_TCP_ResponseDTr trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Dameware_DetectedDameware DetectedDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Dameware_Obtain_InfoDameware Obtain InfoEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Dameware_Spoof_OverflowDameWare spoofed packet buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Danton_TCP_ResponseDanton trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DarkConnectionInside_TCP_RequestDark Connection Inside trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DarkConnectionInside_TCP_ResponseDark Connection Inside trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DeepThroat_ResponseDeepThroat BackdoorEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
Packet
Disabled
DeltaSource_ResponseDeltaSource BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Devil_RequestDevil BackdoorEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DigitalRootBeer_TCP_RequestDigital RootBeer trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
DirectConnect_ConnectDirect Connect connectionDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Doly_ResponseDoly BackdoorEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
DonaldDick_ResponseDonald Dick BackdoorEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
Dtspcd_OverflowDtspcd OverflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
Duddie_TCP_RequestDuddie trojan horse activityEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
EMail_Generic_Intel_OverflowEMAIL Generic Intel OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
EPolicy_Orchestrator_Format_StringEPolicy Orchestrator Format StringEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
EPolicy_Orchestrator_Vulnerable_ServerEPolicy Orchestrator Vulnerable ServerDisabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Echo_Denial_of_ServiceEcho_Denial_of_Service_With_Src_and_Dst_of_7Enabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Echo_Reply_Without_RequestEcho reply without requestEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Edonkey_ConnectEdonkey connectionDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Edonkey_DownloadEdonkey File TransferDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Almail_OverflowE-Mail ALMail pop3 overflow in smtp processing codeEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Amavis_ExecAMaViS EMail Command ExecuteEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Auth_FailedSMTP login failedEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Auth_OverflowSMTP Auth OverflowEnabled MEDIUMDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
Email_BioNetBioNet backdoor email alertEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Command_OverflowSMTP command overflowEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_DataReport SMTP e-mail message bodyDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_DebugE-mail debug attackEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_DecodeSMTP mail to decode aliasEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_EhloE-mail SMTP Ehlo info leakDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Encap_Exch_RelaySTMP encapsulated Exchange relayEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Encap_RelaySMTP encapsulated relayEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Envid_OverflowSMTP ENVID overflowEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_ErrorE-Mail too many errorsEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_ExchangeStore_DoSMicrosoft Exchange Server DoSEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Executable_ExtensionEmail attachment has an executable extensionEnabled MEDIUMDISPLAY RSKILL LOGDB LogWithoutRaw
Disabled Disabled
Email_ExpnDecode SMTP Expn: lineEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Expn_OverflowSMTP Expn OverflowEnabled HIGHDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
Email_False_AttachmentE-Mail false attachmentEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_FromDecode SMTP From: lineDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_From_OverflowE-Mail FROM: field overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Helo_OverflowSMTP login name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_IE_HRAlign_OverflowInternet Explorer HR Align buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_IE_ObjectType_OverflowInternet Explorer Object Type OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Invalid_CommandSMTP corrupted MAIL commandEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Listserv_OverflowSMTP Listserv OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Lotus_DominoLotus_Domino_SMTP_OverflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Mime_FilenameSMTP MIME filenameDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Mime_Filename_BlanksSMTP MIME filename repeated blanksEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Mime_Filename_CharsSMTP MIME filename repeated charsEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Mime_Filename_OverflowE-Mail MIME file name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Mime_Name_OverflowE-Mail MIME name overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Mime_NullE-Mail MIME null character setEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Name_OverflowSMTP email name overflowEnabled MEDIUMDISPLAY LOGDB DROP LogWithoutRaw
ConnectionWithReset
Disabled
Email_Outlook_Date_OverflowE-Mail Outlook Date overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Outlook_URL_SpoofMS Outlook URL spoofingEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_PipeSMTP pipe in mail addressEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Potential_BO_AttachmentPotential buffer overflow in email attachmentEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Qmail_LengthSMTP Qmail length denial of service attackEnabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Qmail_RcptSMTP Qmail RCPT denial of service attackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Rcpt_TooManyQuotesNetscape Directory Server buffer overflowEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Recipient_DotSMTP Recipient with trailing dotEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Recipient_OverflowSMTP Too many recipientsEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Relay_AttemptSMTP relay attemptEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Relay_SpamDecode SMTP Relay % SPAMEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_ReplyTo_ExecutableE-Mail "Reply-To:" is an executableEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_Rpmmail_AliasSMTP mail to rpmmail aliasEnabled HIGHDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_ServerIDSMTP Server IDDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_SubSevenSubSeven backdoor email alertEnabled HIGHDISPLAY LOGDB DROP DYNAMICBLOCK LogWithoutRaw
ConnectionWithReset
IsolateTrojan
Email_SubjectDecode E-Mail Subject: lineDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_ToDecode SMTP To: lineDisabled LOWDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_To_Dot_DotaVirt create directory vulnerabilityEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled Disabled
Email_TurnE-mail SMTP Turn attackEnabled MEDIUMDISPLAY LOGDB LogWithoutRaw
Disabled