Skip to content

Instantly share code, notes, and snippets.

@shadowbq
Created August 29, 2017 13:45
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save shadowbq/38bb16b91f8b2287e3eefda63fe20292 to your computer and use it in GitHub Desktop.
Save shadowbq/38bb16b91f8b2287e3eefda63fe20292 to your computer and use it in GitHub Desktop.
NetworkFlow process, process_id where NetworkFlow src_ip contains 10.250.45.0/24
and NetworkFlow dst_ip equals 10.0.0.2
CurrentFlow process_id where CurrentFlow local_ip contains 10.250.45.0/24 and
CurrentFlow remote_ip equals 10.0.0.2
@shadowbq
Copy link
Author

@shadowbq
Copy link
Author

shadowbq commented Aug 29, 2017

trigger "Network src_ip contains 10.10.0.255/24 and Network dst_ip equals 10.10.0.255/24 and Network dst_port equals 10001"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment