Skip to content
Snippets Groups Projects
Commit ea1a402c authored by pharook's avatar pharook
Browse files

Added tag examples.

parent 8461029b
No related branches found
No related tags found
No related merge requests found
...@@ -88,7 +88,8 @@ C. Description tags ...@@ -88,7 +88,8 @@ C. Description tags
1. Detection medium 1. Detection medium
* Network - network data based (Snort, Suricata, Bro, FTAS, LaBrea, Kippo) * Network - network data based (Snort, Suricata, Bro, FTAS, LaBrea, Kippo,
Dionaea)
* Host - host based (Swatch, Logcheck) * Host - host based (Swatch, Logcheck)
* Correlation - corellation engines (Prelude, OSSIM) * Correlation - corellation engines (Prelude, OSSIM)
* External - credible external sources (incident reporting, ticket * External - credible external sources (incident reporting, ticket
...@@ -97,7 +98,7 @@ C. Description tags ...@@ -97,7 +98,7 @@ C. Description tags
2. Data source 2. Data source
* Content - datagram content based detectors (Snort, Bro) * Content - datagram content based detectors (Snort, Bro)
* Flow - netflow based (FTAS, FlowMon) * Flow - netflow based (FTAS, FlowMon, HoneyScan)
* Connection - connection data (portscan, portsweep) * Connection - connection data (portscan, portsweep)
* Data - application data based (SpamAssassin, antiviruses) * Data - application data based (SpamAssassin, antiviruses)
* Log - based on system logs, where more specific source is not * Log - based on system logs, where more specific source is not
...@@ -113,7 +114,7 @@ C. Description tags ...@@ -113,7 +114,7 @@ C. Description tags
4. Detector/analyzer product name examples 4. Detector/analyzer product name examples
* Snort, FTAS, SpamAssassin, LaBrea, Swatch, Prelude * Snort, FTAS, SpamAssassin, LaBrea, Swatch, Prelude, Kippo, Dionaea
-------------------------------------------------------------------------------- --------------------------------------------------------------------------------
D. Types of events D. Types of events
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment