Name | Modified | Size | Downloads / Week |
---|---|---|---|
Parent folder | |||
successattack | 2012-11-26 | ||
geoinfo | 2012-11-26 | ||
anubistask | 2012-11-26 | ||
README | 2012-11-26 | 790 Bytes | |
Totals: 4 Items | 790 Bytes | 0 |
This folder contains 3 sample ruels to be used with the Prelude Correlator Module. ** SUCCESSATTACK ** This rule triggers whenever 2 or more rules from the same source and port target the same host within the network. Requirements: - Prelude - Prelude Correlator Installation: - python setup.py install ** GEOINFO ** This rule performs geolocalization on the source IP of every event. Requirements: - Prelude - Prelude Correlator - http://ipinfodb.com API key Installation: - insert API key into main.py file - python setup.py install ** ANUBISTASK ** This rule sends the shellcode gathered from the peripheral tools (if they provide it), sends it to Anubis and retrieves the corresponding task id Requirements: - Prelude - Prelude Correlator Installation: - python setup.py install