Snort mailing list archives
a question for Michael Shirk
From: Dorian ROSSE via Snort-sigs <snort-sigs () lists snort org>
Date: Sat, 11 Jan 2020 09:44:11 +0000
Hello dear Michael Shirk,
I have found this doc on my own pulledpork :
Update README.CATEGORIES
Appended a solution to get a list of all categories when they are changed or new.
Removed and wrote the current list of categories.
Replaced "-=" and "=-" which caused all rules to be disabled, and changed to "##".
How to get the current categories (the categories get renamed and changed without notice.):
1.) Configure the rules you want (ET,VRT,Pro,w/OinkCode) pulledpork.pl
2.) Execute the download: /usr/local/bin/pulledpork.pl -c /etc/snort/pulledpork.conf -Pw
3.) Execute this one-liner: lz /var/tmp/*.gz | egrep '\.rules' | cut -d'/' -f3 | sort -u | perl -lne '/(.*).rules/ &&
print $1' > rules.`date +%F
I will run this command line on my home network but must I launch this command line on my red hat server where I have
firstly create this fork for sanitize against e-mail and malware by go-pkg dev works ?
Thank you in advance to asnwer my question,
Regards.
Dorian ROSSE (azaretdodo on github).
_______________________________________________ Snort-sigs mailing list Snort-sigs () lists snort org https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
Current thread:
- a question for Michael Shirk Dorian ROSSE via Snort-sigs (Jan 11)
