SV-80923r1_rule
V-66433
SRG-NET-000248-IDPS-00206
JUSX-IP-000027
CAT II
10
Configure a dynamic custom attack group which includes attack objects for malicious code monitoring of files. There are many ways to accomplish this; thus, the following is only an example:
[edit]
security idp dynamic-attack-group Malicious-Activity
set category values [ SHELLCODE VIRUS WORMS SPYWARE TROJAN]
Verify a dynamic custom attack group which includes attack objects for malicious code monitoring of files.
show security idp dynamic-attack-group
If a custom attack group exists containing members which include malicious code attack categories, this is a finding.
V-66433
False
JUSX-IP-000027
Verify a dynamic custom attack group which includes attack objects for malicious code monitoring of files.
show security idp dynamic-attack-group
If a custom attack group exists containing members which include malicious code attack categories, this is a finding.
M
3037