2 - Official sendmail rules for OSSEC.
4 - Author: Daniel B. Cid
5 - License: http://www.ossec.net/en/licensing.html
9 <group name="syslog,sendmail,">
10 <rule id="3100" level="0">
11 <decoded_as>sendmail-reject</decoded_as>
12 <description>Grouping of the sendmail rules.</description>
15 <rule id="3101" level="0" noalert="1">
17 <match>reject=</match>
18 <description>Grouping of the sendmail reject rules.</description>
21 <rule id="3102" level="5">
23 <match>reject=451 4.1.8 </match>
24 <description>Sender domain does not have any valid </description>
25 <description>MX record (Requested action aborted).</description>
29 <rule id="3103" level="6">
31 <match>reject=550 5.0.0 |reject=553 5.3.0</match>
32 <description>Rejected by access list </description>
33 <description>(55x: Requested action not taken).</description>
37 <rule id="3104" level="6">
39 <match>reject=550 5.7.1 </match>
40 <description>Attepmt to use mail server as relay </description>
41 <description>(550: Requested action not taken).</description>
45 <rule id="3105" level="5">
47 <match>reject=553 5.1.8 </match>
48 <description>Sender domain is not found </description>
49 <description> (553: Requested action not taken).</description>
53 <rule id="3106" level="5">
55 <match>reject=553 5.5.4 </match>
56 <description>Sender address does not have domain </description>
57 <description>(553: Requested action not taken).</description>
61 <rule id="3107" level="4">
63 <description>Sendmail rejected message.</description>
66 <rule id="3108" level="6">
68 <match>rejecting commands from</match>
69 <description>Sendmail rejected due to pre-greeting.</description>
73 <rule id="3109" level="8">
75 <match>savemail panic</match>
76 <description>Sendmail save mail panic.</description>
77 <group>system_error,</group>
80 <rule id="3151" level="10" frequency="6" timeframe="120">
81 <if_matched_sid>3102</if_matched_sid>
83 <description>Sender domain has bogus MX record. </description>
84 <description>It should not be sending e-mail.</description>
85 <group>multiple_spam,</group>
88 <rule id="3152" level="6" frequency="6" timeframe="120">
89 <if_matched_sid>3103</if_matched_sid>
91 <description>Multiple attempts to send e-mail from a </description>
92 <description>previously rejected sender (access).</description>
93 <group>multiple_spam,</group>
96 <rule id="3153" level="6" frequency="6" timeframe="120">
97 <if_matched_sid>3104</if_matched_sid>
99 <description>Multiple relaying attempts of spam.</description>
100 <group>multiple_spam,</group>
103 <rule id="3154" level="10" frequency="6" timeframe="120">
104 <if_matched_sid>3105</if_matched_sid>
106 <description>Multiple attempts to send e-mail </description>
107 <description>from invalid/unknown sender domain.</description>
108 <group>multiple_spam,</group>
111 <rule id="3155" level="10" frequency="6" timeframe="120">
112 <if_matched_sid>3106</if_matched_sid>
114 <description>Multiple attempts to send e-mail from </description>
115 <description>invalid/unknown sender.</description>
116 <group>multiple_spam,</group>
119 <rule id="3156" level="10" frequency="10" timeframe="120">
120 <if_matched_sid>3107</if_matched_sid>
122 <description>Multiple rejected e-mails from same source ip.</description>
123 <group>multiple_spam,</group>
126 <rule id="3158" level="10" frequency="6" timeframe="120">
127 <if_matched_sid>3108</if_matched_sid>
129 <description>Multiple pre-greetings rejects.</description>
130 <group>multiple_spam,</group>
134 <!-- Rules for SMF-SAV -->
135 <rule id="3190" level="0">
136 <decoded_as>smf-sav-reject</decoded_as>
137 <description>Grouping of the smf-sav sendmail milter rules.</description>
138 <group>smf-sav,</group>
141 <rule id="3191" level="6">
142 <if_sid>3190</if_sid>
143 <match>^sender check failed|^sender check tempfailed</match>
144 <description>SMF-SAV sendmail milter unable to verify </description>
145 <description>address (REJECTED).</description>
146 <group>smf-sav,spam,</group>
149 </group> <!-- SYSLOG,SENDMAIL -->