From 139202c0e39976146debbfe09ca6687ebad56047 Mon Sep 17 00:00:00 2001 From: Ad Schellevis Date: Sun, 16 Oct 2016 15:39:00 +0200 Subject: [PATCH] add PT Research ruleset defintion (easy example of the new compressed rule support and demos the prefered method of content distribution for OPNsense/IDS). Their rules come with a different license, hence the note "for non-commercial use". More information about the ruleset and license https://github.com/ptresearch/AttackDetection --- Makefile | 2 +- security/ids-content-pt-research/Makefile | 7 +++++++ .../scripts/suricata/metadata/rules/pt-research.xml | 9 +++++++++ 3 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 security/ids-content-pt-research/Makefile create mode 100644 security/ids-content-pt-research/src/opnsense/scripts/suricata/metadata/rules/pt-research.xml diff --git a/Makefile b/Makefile index 38bcce303..c8d8618a4 100644 --- a/Makefile +++ b/Makefile @@ -3,7 +3,7 @@ PAGER?= less all: @cat ${.CURDIR}/README.md | ${PAGER} -CATEGORIES= devel net sysutils +CATEGORIES= devel net sysutils security .for CATEGORY in ${CATEGORIES} _${CATEGORY}!= ls -1d ${CATEGORY}/* diff --git a/security/ids-content-pt-research/Makefile b/security/ids-content-pt-research/Makefile new file mode 100644 index 000000000..0b0db0d5f --- /dev/null +++ b/security/ids-content-pt-research/Makefile @@ -0,0 +1,7 @@ +PLUGIN_NAME= ids-content-pt-research +PLUGIN_VERSION= 1.0 +PLUGIN_REVISION= 1 +PLUGIN_COMMENT= IDS PT Research ruleset (only for non-commercial use) +PLUGIN_MAINTAINER= ad@opnsense.org + +.include "../../Mk/plugins.mk" diff --git a/security/ids-content-pt-research/src/opnsense/scripts/suricata/metadata/rules/pt-research.xml b/security/ids-content-pt-research/src/opnsense/scripts/suricata/metadata/rules/pt-research.xml new file mode 100644 index 000000000..15c13cea0 --- /dev/null +++ b/security/ids-content-pt-research/src/opnsense/scripts/suricata/metadata/rules/pt-research.xml @@ -0,0 +1,9 @@ + + + + + pt.research.rules + +