Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Rules changes 2019 04.v6 #580

Merged
merged 2 commits into from
Apr 12, 2019
Merged

Rules changes 2019 04.v6 #580

merged 2 commits into from
Apr 12, 2019

Conversation

mstemm
Copy link
Contributor

@mstemm mstemm commented Apr 12, 2019

No description provided.

We'll try to limit the list to programs that can broadly see activity or
actually create traffic.
Replace "Unexpected outbound connection source" with "Unexpected inbound
connection source" to watch inbound connections by source instead of
outbound connections by source. The rule itself is pretty much unchanged
other than switching to using cip/cnet instead of sip/snet.

Expand the supporting macros so they include outbound/inbound in the
name, to make it clearer.
@mstemm mstemm requested a review from Kaizhe April 12, 2019 17:26
Copy link
Contributor

@Kaizhe Kaizhe left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mstemm mstemm merged commit 0e31ae5 into dev Apr 12, 2019
@mstemm mstemm deleted the rules-changes-2019-04.v6 branch April 12, 2019 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants