cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
279
Views
0
Helpful
2
Replies

OS classification of signatures

gpoer
Level 1
Level 1

Has anyone gone through and classified the signatures by Operating System (perhaps even patch level). I understand that not all signatures would fall into such a category (Host scanning sigs being an example) but the information is very useful if you can drop alarms that do not apply to your environment.

We are looking to run the gambit and classify the sigs but I am hoping that it has already been done :)

thanks,

Geoff

2 Replies 2

stleary
Cisco Employee
Cisco Employee

IDM 4.0 categorizes signatures by operating system.

You can enable or disable signatures within each

operating system category.

How can I dump that information?

Is it accessable with RDEP? If so do you know what the schema would be?

thanks, geoff

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: