X-Git-Url: http://ftp.carnet.hr/carnet-debian/scm?p=ossec-hids.git;a=blobdiff_plain;f=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fossec_rules.xml;fp=debian%2Fossec-hids%2Fvar%2Fossec%2Frules%2Fossec_rules.xml;h=0000000000000000000000000000000000000000;hp=7de90f58a88d0c83b96fde64a3f545fb1388aeca;hb=946517cefb8751a43a89bda4220221f065f4e5d1;hpb=3f728675941dc69d4e544d3a880a56240a6e394a diff --git a/debian/ossec-hids/var/ossec/rules/ossec_rules.xml b/debian/ossec-hids/var/ossec/rules/ossec_rules.xml deleted file mode 100644 index 7de90f5..0000000 --- a/debian/ossec-hids/var/ossec/rules/ossec_rules.xml +++ /dev/null @@ -1,362 +0,0 @@ - - - - - - - ossec - ossec - Grouping of ossec rules. - - - - 500 - - alert_by_email - Agent started - New ossec agent connected. - - - - 500 - alert_by_email - Ossec started - Ossec server started. - - - - 500 - alert_by_email - Agent started - Ossec agent started. - - - - 500 - alert_by_email - Agent disconnected - Ossec agent disconnected. - - - - ossec - rootcheck - Rootcheck event. - rootcheck, - - - - 509 - Host-based anomaly detection event (rootcheck). - rootcheck, - - - - - 510 - ^NTFS Alternate data stream found - Thumbs.db:encryptable'.|:Zone.Identifier'.| - Exchsrvr/Mailroot/vsi - Ignored common NTFS ADS entries. - rootcheck, - - - - 510 - ^Windows Audit - Windows Audit event. - rootcheck, - - - - 510 - ^Windows Malware - Windows malware detected. - rootcheck, - - - - 510 - ^Application Found - Windows application monitor event. - rootcheck, - - - - 510 - ^Starting rootcheck scan|^Ending rootcheck scan.| - ^Starting syscheck scan|^Ending syscheck scan. - Ignoring rootcheck/syscheck scan messages. - rootcheck,syscheck - - - - 510 - ^System Audit - System Audit event. - rootcheck, - - - - 514 - Adware|Spyware - Windows Adware/Spyware application found. - rootcheck, - - - - 516 - ^System Audit: Web vulnerability - System Audit: Vulnerable web application found. - rootcheck, - - - - - 500 - ^ossec: output: - OSSEC process monitoring rules. - process_monitor, - - - - 530 - ossec: output: 'df -P': /dev/ - 100% - Partition usage reached 100% (disk space monitor). - low_diskspace, - - - - 531 - cdrom|/media|usb|/mount|floppy|dvd - Ignoring external medias. - - - - 530 - ossec: output: 'netstat -tan - - Listened ports status (netstat) changed (new port opened or closed). - - - - 530 - ossec: output: 'w' - - no_log - List of logged in users. It will not be alerted by default. - - - - 530 - ossec: output: 'last -n - - no_log - List of the last logged in users. - - - - ossec - syscheck_integrity_changed - Integrity checksum changed. - syscheck, - - - - ossec - syscheck_integrity_changed_2nd - Integrity checksum changed again (2nd time). - syscheck, - - - - ossec - syscheck_integrity_changed_3rd - Integrity checksum changed again (3rd time). - syscheck, - - - - ossec - syscheck_deleted - File deleted. Unable to retrieve checksum. - syscheck, - - - - ossec - syscheck_new_entry - File added to the system. - syscheck, - - - - 500 - ^ossec: agentless: - Integrity checksum for agentless device changed. - syscheck,agentless - - - - - ossec - hostinfo_modified - Host information changed. - hostinfo, - - - - ossec - hostinfo_new - Host information added. - hostinfo, - - - - - - 500 - ^ossec: File rotated - Log file rotated. - - - - 500 - ^ossec: File size reduced - Log file size reduced. - attacks, - - - - 500 - ^ossec: Event log cleared - Microsoft Event log cleared. - logs_cleared, - - - - ossec - 550 - syscheck-registry - syscheck, - Registry Integrity Checksum Changed - - - - ossec - 551 - syscheck-registry - syscheck, - Registry Integrity Checksum Changed Again (2nd time) - - - - ossec - 552 - syscheck-registry - syscheck, - Registry Integrity Checksum Changed Again (3rd time) - - - - ossec - 553 - syscheck-registry - syscheck, - Registry Entry Deleted. Unable to Retrieve Checksum - - - - ossec - 554 - syscheck-registry - syscheck, - Registry Entry Added to the System - - - - - - ar_log - Active Response Messages Grouped - active_response, - - - - 600 - firewall-drop.sh - add - Host Blocked by firewall-drop.sh Active Response - active_response, - - - - 600 - firewall-drop.sh - delete - Host Unblocked by firewall-drop.sh Active Response - active_response, - - - - 600 - host-deny.sh - add - Host Blocked by host-deny.sh Active Response - active_response, - - - - 600 - host-deny.sh - delete - Host Unblocked by host-deny.sh Active Response - active_response, - - - - 600 - route-null.sh - add - Host Blocked by route-null.sh Active Response - active_response, - - - - 600 - route-null.sh - delete - Host Unblocked by route-null.sh Active Response - active_response, - - - - ossec - ossec-logcollector - Logcollector Messages Grouped - - - - 700 - INFO: - Ignore informational messages (usually at startup) - - -