ISS RealSecure Network Sensor Policy
[ issPolicy v1.01 | http://packet.sequenced.org/projects/isspolicy ]



POLICY INFORMATION

   Policy File: policies/AttackDetector.policy
   Policy Name: Attack Detector
   Policy Version: 7.0.2003.59
   Sensor Type: RealSecure Network Sensor (v7.0)


SIGNATURES POLICY

Response Summary Legend: DISPLAY | LOGDB | EMAIL | SNMP | RSKILL | OPSEC | LOGEVIDENCE | VIEWSESSION

Signature NameSignature DescriptionSignature StatusSignature PriorityResponse SummaryLog
AOLIM_File_XferAOL Instant Messenger file transferDisabled LOWDISPLAY LOGDB LogWithoutRaw
AOLIM_LoginAOL Instant Messenger loginDisabled LOWDISPLAY LOGDB LogWithoutRaw
AOLIM_MessageAOL Instant Messenger messageDisabled LOWDISPLAY LOGDB LogWithoutRaw
AOLIM_Password_ChangeAOL Instant Messenger password changeDisabled LOWDISPLAY LOGDB LogWithoutRaw
AOLIM_Trillian_Encrypt_HandshakeTrillian encrypted messaging handshakeDisabled LOWDISPLAY LOGDB LogWithoutRaw
AUDIT_DNS_Version_RequestBind Version Information RequestedDisabled LOWDISPLAY LOGDB LogWithoutRaw
BGP_New_RouteBGP new route advertisementDisabled LOWDISPLAY LOGDB LogWithoutRaw
BGP_Notify_MsgBGP notification messageDisabled LOWDISPLAY LOGDB LogWithoutRaw
BGP_Route_UnreachableBGP route has become unreachableDisabled LOWDISPLAY LOGDB LogWithoutRaw
DHCP_AckDHCP AckDisabled LOWDISPLAY LOGDB LogWithoutRaw
DHCP_DiscoverDHCP DiscoverDisabled LOWDISPLAY LOGDB LogWithoutRaw
DHCP_RequestDHCP RequestDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_DataReport SMTP e-mail message bodyDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_EhloE-mail SMTP Ehlo info leakDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_FromDecode SMTP From: lineDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_Mime_FilenameSMTP MIME filenameDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_ServerIDSMTP Server IDDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_SubjectDecode E-Mail Subject: lineDisabled LOWDISPLAY LOGDB LogWithoutRaw
Email_ToDecode SMTP To: lineDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_FilenameFTP File NameDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_GetDecode FTP get file commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_MkdirDecode FTP mkdir commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_PortFTP Port CommandDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_PutDecode FTP put file commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_Server_IdentityFTP Server IdentityDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_SystFTP SYST command decodeDisabled LOWDISPLAY LOGDB LogWithoutRaw
FTP_UserDecode FTP username commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
FastTrack_DownloadFastTrack DownloadDisabled LOWDISPLAY LOGDB LogWithoutRaw
Gnutella_BearShareGnutella BearShareDisabled LOWDISPLAY LOGDB LogWithoutRaw
Gnutella_ConnectGnutella connectionDisabled LOWDISPLAY LOGDB LogWithoutRaw
Gnutella_DownloadGnutella file transferDisabled LOWDISPLAY LOGDB LogWithoutRaw
Gnutella_LimeWireGnutella LimeWireDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_AuthenticationHTTP authentication decodeDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_CookieHTTP Cookie Passing CheckDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_EDonkeyHTTP EDonkeyDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_GetDecode HTTP get commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_GetArgHTTP Get ArgDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_Java_ClassJava Class URLDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_KazaaHTTP KaZaADisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_PostDecode HTTP Post commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_Post_FieldHTTP Post FieldDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_RobotsTxtHTTP Robots.txt probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_Server_IDHTTP Server IDDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_TrendVCS_Auth_BypassTrend VCS stores passwords using weak encryption algorithmDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_User_AgentHTTP User AgentDisabled LOWDISPLAY LOGDB LogWithoutRaw
HTTP_Vulnerable_ClientHTTP Vulnerable Client CheckDisabled LOWDISPLAY LOGDB LogWithoutRaw
IMAP_LoginDecode IMAP usernameDisabled LOWDISPLAY LOGDB LogWithoutRaw
IP_Unknown_ProtocolDetect unknown IP protocolDisabled LOWDISPLAY LOGDB LogWithoutRaw
IRC_JoinIRC join channel decodeDisabled LOWDISPLAY LOGDB LogWithoutRaw
IRC_Join_AttemptIRC join attemptDisabled LOWDISPLAY LOGDB LogWithoutRaw
IRC_MsgIRC message decodeDisabled LOWDISPLAY LOGDB LogWithoutRaw
IRC_NickIRC nick change decodeDisabled LOWDISPLAY LOGDB LogWithoutRaw
IRC_NoticeIRC notice message decodeDisabled LOWDISPLAY LOGDB LogWithoutRaw
Ident_UserIdent user requestDisabled LOWDISPLAY LOGDB LogWithoutRaw
MSMessenger_LoginMicrosoft Messenger loginDisabled LOWDISPLAY LOGDB LogWithoutRaw
MSMessenger_MessageMicrosoft Messenger messageDisabled LOWDISPLAY LOGDB LogWithoutRaw
MSRPC_Registry_KeyWindows remote registry key accessDisabled LOWDISPLAY LOGDB LogWithoutRaw
MSRPC_Registry_WriteReport MSRPC Windows registry write commandDisabled LOWDISPLAY LOGDB LogWithoutRaw
NNTP_GroupDecode NNTP groupDisabled LOWDISPLAY LOGDB LogWithoutRaw
NNTP_SubjectDecode NNTP subjectDisabled LOWDISPLAY LOGDB LogWithoutRaw
NTP_TimeReport Network Time Protocol timeDisabled LOWDISPLAY LOGDB LogWithoutRaw
Napster_Client_UpdateNapster client updateDisabled LOWDISPLAY LOGDB LogWithoutRaw
Napster_Create_AccountNapster create accountDisabled LOWDISPLAY LOGDB LogWithoutRaw
Napster_DownloadNapster downloadDisabled LOWDISPLAY LOGDB LogWithoutRaw
Napster_LoginNapster loginDisabled LOWDISPLAY LOGDB LogWithoutRaw
Napster_Login_InfoNapster login informationDisabled LOWDISPLAY LOGDB LogWithoutRaw
Napster_Private_MsgNapster private messageDisabled LOWDISPLAY LOGDB LogWithoutRaw
Napster_Public_MsgNapster public messageDisabled LOWDISPLAY LOGDB LogWithoutRaw
Napster_SearchNapster searchDisabled LOWDISPLAY LOGDB LogWithoutRaw
Napster_SharingNapster sharingDisabled LOWDISPLAY LOGDB LogWithoutRaw
Netbios_Session_GrantedDecode NetBIOS session grantsDisabled LOWDISPLAY LOGDB LogWithoutRaw
Netbios_Session_RejectedDecode NetBIOS session rejectsDisabled LOWDISPLAY LOGDB LogWithoutRaw
Netbios_Session_RequestDecode NetBIOS session requestsDisabled LOWDISPLAY LOGDB LogWithoutRaw
Nmap_OS_FingerprintNmap OS fingerprintDisabled LOWDISPLAY LOGDB LogWithoutRaw
POP_FilenamePOP3 File NameDisabled LOWDISPLAY LOGDB LogWithoutRaw
POP_Server_IdentityDecode POP BannerDisabled LOWDISPLAY LOGDB LogWithoutRaw
POP_UserDecode POP usernameDisabled LOWDISPLAY LOGDB LogWithoutRaw
Packet_Capturing_RemoteRemote use of packet capturing toolsDisabled LOWDISPLAY LOGDB LogWithoutRaw
RIP_AddRIP Add RouteDisabled LOWDISPLAY LOGDB LogWithoutRaw
RIP_ExpireRIP Expire RouteDisabled LOWDISPLAY LOGDB LogWithoutRaw
RIP_Metric_ChangeRIP Metric ChangeDisabled LOWDISPLAY LOGDB LogWithoutRaw
RPC_Mountd_MntDecode NFS mount requestDisabled LOWDISPLAY LOGDB LogWithoutRaw
RPC_Portmap_GetportReport RPC Portmapper get port requestsDisabled LOWDISPLAY LOGDB LogWithoutRaw
SMB_FilenameSMB FilenameDisabled LOWDISPLAY LOGDB LogWithoutRaw
SMB_LSA_ConnectRemote connection to Windows NT LSA (possible information gathering)Disabled LOWDISPLAY LOGDB LogWithoutRaw
SOCKS4_ConnectSOCKS 4 ConnectionDisabled LOWDISPLAY LOGDB LogWithoutRaw
SOCKS5_ConnectSOCKS 5 ConnectionDisabled LOWDISPLAY LOGDB LogWithoutRaw
SQL_LoginMicrosoft SQL Server/Sybase loginDisabled LOWDISPLAY LOGDB LogWithoutRaw
SSH_VersionSecure Shell (SSH) presentDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_ACK_PingTCP ACK pingDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_FIN_ScanTCP FIN scanDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Null_ScanTCP Null scanDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_OS_FingerprintTCP OS fingerprintDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_DNSDNS TCP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_FingerFINGER port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_FtpFTP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_GnutellaTCP Probe GnutellaDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_HTTPHTTP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_IRCIRC port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_IdentIDENT port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_Imap4IMAP4 port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_LinuxConfLinux conf port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_LprLPR port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_MSRPCMicrosoft RPC TCP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_NNTPNNTP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_NetBIOSNetBIOS port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_NetbusNetbus probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_OtherTCP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_POP3POP3 port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_PPTPPPTP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_ProxyProxy port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_RloginRlogin port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_SMTPSMTP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_SQLSQL port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_SocksSOCKS port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_SunRPCRPC TCP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_T0rnT0rn port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_TelnetTelnet port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_TrojanTCP trojan horse probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Probe_XWindowsX-Windows port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
TCP_Xmas_ScanTCP Xmas scanDisabled LOWDISPLAY LOGDB LogWithoutRaw
Talk_RequestDecode talk requestDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_Auth_Kerb4Telnet using Kerberos4 authenticationDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_Auth_Kerb5Telnet using Kerberos5 authenticationDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_Auth_LokiTelnet using Loki authenticationDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_Auth_NullTelnet using null authenticationDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_Auth_RsaTelnet using RSA authenticationDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_Auth_SpxTelnet using SPX authenticationDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_Auth_UserTelnet using user authenticationDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_Env_AllTelnet environment variablesDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_LoginTelnet Login NameDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_Terminal_TypeTelnet terminal type optionDisabled LOWDISPLAY LOGDB LogWithoutRaw
Telnet_XdisplayTelnet X display optionDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_CharGenCHARGEN port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_DNSDNS UDP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_EchoUDP ECHO port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_MSDNSMicrosoft DNS port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_MSRPCMicrosoft RPC UDP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_NFSNFS port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_NFS_LockdNFS-LOCKD port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_Norton_AVNorton Antivirus port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_OtherUDP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_QotdQOTD port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_SNMPSNMP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_TFTPTFTP port probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
UDP_Probe_TrojanUDP Trojan Horse probeDisabled LOWDISPLAY LOGDB LogWithoutRaw
VNC_DetectedVNC session detectedDisabled LOWDISPLAY LOGDB LogWithoutRaw
Windows_Access_ErrorErrors while connecting to Windows serversDisabled LOWDISPLAY LOGDB LogWithoutRaw
Windows_Null_SessionWindows null session login (possible anonymous user backdoor)Disabled LOWDISPLAY LOGDB LogWithoutRaw
YahooMSG_File_TransferYahoo Messaging file transferDisabled LOWDISPLAY LOGDB LogWithoutRaw
YahooMSG_LoginYahoo Messaging loginDisabled LOWDISPLAY LOGDB LogWithoutRaw
YahooMSG_MessageYahoo Messaging messageDisabled LOWDISPLAY LOGDB LogWithoutRaw
pcAnywhere_LoginDetect pcAnywhere loginsDisabled LOWDISPLAY LOGDB LogWithoutRaw


USER-DEFINED IP FILTERS

Filter NameFilter DescriptionFilter StatusProtocolSource Address/Mask [Asset]Source PortDestination Address/Mask [Asset]Destination Port



USER-DEFINED EVENT FILTERS

Filter NameFilter DescriptionFilter StatusFiltered EventSource AddressSource PortDestination AddressDestination Port


[ Generated using: issPolicy v1.01 - http://packet.sequenced.org/projects/isspolicy ] [ Author: Kristof Philipsen / kphilipsen@gmail.com ]