X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?a=blobdiff_plain;ds=sidebyside;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fossec_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fossec_rules.xml;h=7de90f58a88d0c83b96fde64a3f545fb1388aeca;hb=3f728675941dc69d4e544d3a880a56240a6e394a;hp=0000000000000000000000000000000000000000;hpb=927951d1c1ad45ba9e7325f07d996154a91c911b;p=ossec-hids.git diff --git a/debian/ossec-hids/var/ossec/rules/ossec_rules.xml b/debian/ossec-hids/var/ossec/rules/ossec_rules.xml new file mode 100644 index 0000000..7de90f5 --- /dev/null +++ b/debian/ossec-hids/var/ossec/rules/ossec_rules.xml @@ -0,0 +1,362 @@ + + + + + + + ossec + ossec + Grouping of ossec rules. + + + + 500 + + alert_by_email + Agent started + New ossec agent connected. + + + + 500 + alert_by_email + Ossec started + Ossec server started. + + + + 500 + alert_by_email + Agent started + Ossec agent started. + + + + 500 + alert_by_email + Agent disconnected + Ossec agent disconnected. + + + + ossec + rootcheck + Rootcheck event. + rootcheck, + + + + 509 + Host-based anomaly detection event (rootcheck). + rootcheck, + + + + + 510 + ^NTFS Alternate data stream found + Thumbs.db:encryptable'.|:Zone.Identifier'.| + Exchsrvr/Mailroot/vsi + Ignored common NTFS ADS entries. + rootcheck, + + + + 510 + ^Windows Audit + Windows Audit event. + rootcheck, + + + + 510 + ^Windows Malware + Windows malware detected. + rootcheck, + + + + 510 + ^Application Found + Windows application monitor event. + rootcheck, + + + + 510 + ^Starting rootcheck scan|^Ending rootcheck scan.| + ^Starting syscheck scan|^Ending syscheck scan. + Ignoring rootcheck/syscheck scan messages. + rootcheck,syscheck + + + + 510 + ^System Audit + System Audit event. + rootcheck, + + + + 514 + Adware|Spyware + Windows Adware/Spyware application found. + rootcheck, + + + + 516 + ^System Audit: Web vulnerability + System Audit: Vulnerable web application found. + rootcheck, + + + + + 500 + ^ossec: output: + OSSEC process monitoring rules. + process_monitor, + + + + 530 + ossec: output: 'df -P': /dev/ + 100% + Partition usage reached 100% (disk space monitor). + low_diskspace, + + + + 531 + cdrom|/media|usb|/mount|floppy|dvd + Ignoring external medias. + + + + 530 + ossec: output: 'netstat -tan + + Listened ports status (netstat) changed (new port opened or closed). + + + + 530 + ossec: output: 'w' + + no_log + List of logged in users. It will not be alerted by default. + + + + 530 + ossec: output: 'last -n + + no_log + List of the last logged in users. + + + + ossec + syscheck_integrity_changed + Integrity checksum changed. + syscheck, + + + + ossec + syscheck_integrity_changed_2nd + Integrity checksum changed again (2nd time). + syscheck, + + + + ossec + syscheck_integrity_changed_3rd + Integrity checksum changed again (3rd time). + syscheck, + + + + ossec + syscheck_deleted + File deleted. Unable to retrieve checksum. + syscheck, + + + + ossec + syscheck_new_entry + File added to the system. + syscheck, + + + + 500 + ^ossec: agentless: + Integrity checksum for agentless device changed. + syscheck,agentless + + + + + ossec + hostinfo_modified + Host information changed. + hostinfo, + + + + ossec + hostinfo_new + Host information added. + hostinfo, + + + + + + 500 + ^ossec: File rotated + Log file rotated. + + + + 500 + ^ossec: File size reduced + Log file size reduced. + attacks, + + + + 500 + ^ossec: Event log cleared + Microsoft Event log cleared. + logs_cleared, + + + + ossec + 550 + syscheck-registry + syscheck, + Registry Integrity Checksum Changed + + + + ossec + 551 + syscheck-registry + syscheck, + Registry Integrity Checksum Changed Again (2nd time) + + + + ossec + 552 + syscheck-registry + syscheck, + Registry Integrity Checksum Changed Again (3rd time) + + + + ossec + 553 + syscheck-registry + syscheck, + Registry Entry Deleted. Unable to Retrieve Checksum + + + + ossec + 554 + syscheck-registry + syscheck, + Registry Entry Added to the System + + + + + + ar_log + Active Response Messages Grouped + active_response, + + + + 600 + firewall-drop.sh + add + Host Blocked by firewall-drop.sh Active Response + active_response, + + + + 600 + firewall-drop.sh + delete + Host Unblocked by firewall-drop.sh Active Response + active_response, + + + + 600 + host-deny.sh + add + Host Blocked by host-deny.sh Active Response + active_response, + + + + 600 + host-deny.sh + delete + Host Unblocked by host-deny.sh Active Response + active_response, + + + + 600 + route-null.sh + add + Host Blocked by route-null.sh Active Response + active_response, + + + + 600 + route-null.sh + delete + Host Unblocked by route-null.sh Active Response + active_response, + + + + ossec + ossec-logcollector + Logcollector Messages Grouped + + + + 700 + INFO: + Ignore informational messages (usually at startup) + + +