Event Types

dmz-outbound

Search terms: src_ip=10*
Categories:
Updated: 8 months ago Added:8 months ago
Rating: Awaiting 3 votes

terminated_accounts

Search terms: user=example1 OR user=example2
Categories:
Updated: 11 months ago Added:11 months ago
Rating: Awaiting 3 votes

traffic-outbound

Search terms: src_ip=192.168.* OR src_ip=10.* OR src_ip=172.16.* NOT dest_ip=192.168.* NOT dest_ip=10.* NOT dest_ip=172.16.*
Categories:
Updated: 8 months ago Added:8 months ago
Rating: Awaiting 3 votes

insecure-services

Search terms: process=ftp OR process=telnet OR process=rlogin
Categories:
Updated: 11 months ago Added:11 months ago
Rating: Awaiting 3 votes

default-account

Search terms: user=root OR user=administrator OR user=guest
Categories:
Updated: 11 months ago Added:11 months ago
Rating: Awaiting 3 votes

wireless-dest

Search terms: dest_network=wireless
Categories:
Updated: 11 months ago Added:11 months ago
Rating: Awaiting 3 votes

dest_whitelist

Search terms: dest_ip=127.0.0.1 OR dest_ip=192.168.* OR dest_ip=10.* OR dest_ip=176.16.*
Categories:
Updated: 11 months ago Added:11 months ago
Rating: Awaiting 3 votes

dmz-inbound

Search terms: dest_ip=10*
Categories:
Updated: 8 months ago Added:8 months ago
Rating: Awaiting 3 votes

service_accounts

Search terms: user=uucp OR user=mysql OR user=apache OR user=www OR user=oracle OR user=wwwrun OR user=telnet OR user=ppp
Categories:
Updated: 11 months ago Added:11 months ago
Rating: Awaiting 3 votes

insecure-ports

Search terms: dest_port=23 OR dest_port=69 or dest_port=80
Categories:
Updated: 8 months ago Added:8 months ago
Rating: Awaiting 3 votes

traffic-inbound

Search terms: dest_ip=192.168.* OR dest_ip=10.* OR dest_ip=172.16.* NOT src_ip=192.168.* NOT src_ip=10.* NOT src_ip=172.16.*
Categories:
Updated: 8 months ago Added:8 months ago
Rating: Awaiting 3 votes

wireless-src

Search terms: src_network=wireless
Categories:
Updated: 11 months ago Added:11 months ago
Rating: Awaiting 3 votes

src_whitelist

Search terms: src_ip=127.0.0.1 OR src_ip=192.168.* OR src_ip=10.* OR src_ip=176.16.*
Categories:
Updated: 11 months ago Added:11 months ago
Rating: Awaiting 3 votes