OSSEC Rules
•OSSEC rules are stored as XML files
•Rules are hierarchical
•By default OSSEC includes rules for:
apache, arpwatch, asterisk, cisco-ios, courier, firewalls,
ftpd, horde/imp, IDS systems, IMAP, McAfee antivirus,
MS auth, MS DHCP, Exchange, Microsoft FTPD,
MySQL, Bind, Netscreen, PAM, postfix, Postgres,
ProFTP, Roundcube, sendmail, samba, Squit, SSH,
Symantec AV, Syslog, Telnet, VMWare, VSFTP,
Wordpress, and more...
©Justin C. Klein Keane
<
[email protected]>