From 36ea34ecf9c019aebe9e26a8e963ae15f1b2c77a Mon Sep 17 00:00:00 2001 From: Michael Clemens Date: Thu, 22 Mar 2018 15:41:33 +0100 Subject: [PATCH] added demo.xml and Markdown output --- demo/demo.mk | 66 ++++++++++++++++++++++++++++++++++++++ demo/demo.xml | 87 +++++++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 153 insertions(+) create mode 100644 demo/demo.mk create mode 100644 demo/demo.xml diff --git a/demo/demo.mk b/demo/demo.mk new file mode 100644 index 0000000..5273fd4 --- /dev/null +++ b/demo/demo.mk @@ -0,0 +1,66 @@ + +# Correlation Rule Overview + +* **Demo Correlation Rule** + +# Demo Correlation Rule + +## Description +This correlation rule is for demo purposes only. It makes no sense at all and is only needed to test esm2markdown. + +## General Information +* **Rule ID:** 47-6000112 +* **Normalization ID:** 4026531840 +* **Severity:** 50 +* **Tag:** Demo Correlation Rules +* **Group By:** SRC_ZONE + +## Correlation Details +![](images/47-6000112.png) + + + +### Parameters +* **Demo Parameter** + * **Description:** This parameter is a parameter. + * **Default Value:** UserIDSrc|6751494449278544611[root] + +### Rules + +#### Rule 1 +* **Activate:** EVENT +* **Match Type:** FILTER + * **Count:** 1 +* **Action:** Trigger + * **Timeout:** 600 + * **Time Units:** SECOND + * **Threshold:** 5 +* **Match Filter** + * **Filter Component** + * **Condition:** 'SRC_IP' EQUALS '1.1.1.1' + +#### Rule 2 +* **Activate:** EVENT +* **Match Type:** FILTER + * **Count:** 1 +* **Action:** Trigger + * **Timeout:** 600 + * **Time Units:** SECOND + * **Threshold:** 5 +* **Match Filter** + * **Filter Component** + * **Condition:** 'CUST_4259873' EQUALS 'Description|12622590293378144023[bla]' + +#### Rule 3 +* **Activate:** EVENT +* **Match Type:** FILTER + * **Count:** 1 +* **Action:** Trigger + * **Timeout:** 600 + * **Time Units:** SECOND + * **Threshold:** 1 +* **Match Filter** + * **Filter Component** + * **Condition:** 'CUST_2' EQUALS 'CommandID|6751494449278544611[$var=PRIVILEGED_USERS]' + +\newpage diff --git a/demo/demo.xml b/demo/demo.xml new file mode 100644 index 0000000..8c68517 --- /dev/null +++ b/demo/demo.xml @@ -0,0 +1,87 @@ + + + + + 47-6000112 + 4026531840 + 38144 + 0 + 0 + Demo Correlation Rule + This correlation rule is for demo purposes only. It makes no sense at all and is only needed to test esm2markdown. + 1 + 50 + 13 + 255 + 255 + 0 + 4 + 0 + + + + + + + trigger_1 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + sigid + 6000112 + + + rev + 9.5.0 + + + user + 8213 + + + forbid + F + + +]]> + Demo Correlation Rules + + +