Sample Bro Policy

From BroWiki

Jump to: navigation, search

Do you have some Bro policy code that others might find useful? Request a wiki account and post it here!

    (1) domain names that look like host.local.com.evil.com 
(2) lookups that return 127.0.0.0/8, 10.0.0.0/8 or 192.168.0.0/16 addresses. Further lookups providing new address information are logged as well. These transitions have been used for bot C&C before.
     /modules/Forums/admin/admin_db_utilities.php?phpbb_root_path=hxxp://usuarios.arnet.com.ar/larry123/safe.txt?
the download address is parsed put of the URI and possibly resolved. Another 'when' example!

Connections to these addresses are flagged as hot and alarmed.

Personal tools