[Oisf-users] How to alert for a single TCP packet?

Lucas Augusto Mota de Alcantara lama2 at cin.ufpe.br
Mon Nov 25 16:56:27 UTC 2019


Sure, here it is.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20191125/2ba275aa/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: tcp-stream.pcap
Type: application/vnd.tcpdump.pcap
Size: 53097 bytes
Desc: not available
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20191125/2ba275aa/attachment-0002.pcap>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: single-packet.pcap
Type: application/vnd.tcpdump.pcap
Size: 289 bytes
Desc: not available
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20191125/2ba275aa/attachment-0003.pcap>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: testing.rules
Type: application/octet-stream
Size: 354 bytes
Desc: not available
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20191125/2ba275aa/attachment-0001.obj>


More information about the Oisf-users mailing list