DISPLAY |
LOGDB |
EMAIL |
SNMP |
RSKILL |
OPSEC |
LOGEVIDENCE |
DROP |
DYNAMICBLOCK| Signature Name | Signature Description | Signature Status | Signature Priority | Response Summary | Log | Drop | DynamicBlock |
| HTTP_Code_Red | Code Red I | Enabled | HIGH | | LogWithoutRaw |
ConnectionWithReset |
BlockWorm |
| HTTP_Code_Red_II | Code Red II | Enabled | HIGH | | LogWithoutRaw |
ConnectionWithReset |
BlockWorm |
| HTTP_Code_Red_II_Plus | Code Red II+ | Enabled | HIGH | | LogWithoutRaw |
ConnectionWithReset |
BlockWorm |
| IRC_PrettyPark_Worm | PrettyPark worm | Enabled | HIGH | | LogWithoutRaw |
ConnectionWithReset |
BlockWorm |
| Filter Name | Filter Description | Filter Status | Protocol | Source Address/Mask [Asset] | Source Port | Destination Address/Mask [Asset] | Destination Port |
| FR-PAR-NESSUS | Internet Scanner Vulnerability Assessment host (Paris, France) | Enabled | ip | 1.2.3.4/32 | ANY | ANY | ANY |
| UK-LON-NESSUS | Internet Scanner Vulnerability Assessment host (London, United Kingdom) | Enabled | ip | 4.3.2.1/32 | ANY | ANY | ANY |
| Filter Name | Filter Description | Filter Status | Filtered Event | Source Address | Source Port | Destination Address | Destination Port |
| MY-KUL-HTTP-001 | Microsoft ASP.NET vulnerability against Apache web server (Kuala Lumpur, Malaysia) | Disabled | HTTP_ASP_Security_Bypass | ANY | ANY | 3.3.3.3 | 80 |