<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: alienvault ossim alerts on netapp storage in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/alienvault-ossim-alerts-on-netapp-storage/m-p/120406#M25794</link>
    <description>&lt;P&gt;u might need to open a case about it&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jun 2016 04:21:51 GMT</pubDate>
    <dc:creator>Jeff_Yao</dc:creator>
    <dc:date>2016-06-21T04:21:51Z</dc:date>
    <item>
      <title>alienvault ossim alerts on netapp storage</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/alienvault-ossim-alerts-on-netapp-storage/m-p/120047#M25728</link>
      <description>&lt;P&gt;hi!&lt;/P&gt;&lt;P&gt;we are currently using alienvault ossim as our siem soultion.&lt;/P&gt;&lt;P&gt;and for some reason we continuously getting "Malware infection" on the netapp ip.&lt;/P&gt;&lt;P&gt;AlienVault NIDS: "ET TROJAN Linux/dtool IRC Command (TCPFLOOD)"&lt;/P&gt;&lt;P&gt;suricate alert:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;inux/dtool IRC Command (TCPFLOOD)"; flow:established,from_server; content:"PRIVMSG"; content:"{TCPFLOOD}"; fast_pattern; nocase; content:"Started sending tcp data to host"; distance:0; reference:url,kernelmode.info/forum/viewtopic.php?f=16&amp;amp;t=4048&amp;amp;p=26845#p26845; reference:md5,a60b96a2cf4b979968fe5ac6259fb197; classtype:trojan-acti.......4........WV...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;......................&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;....vD.)F.@....................WV..WV...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;........... . .....{.8..E.....@.@.Y&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;....vD.)F.@...P@.5......l.....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;amp;....n..vity; sid:2021873; rev:3;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET any (msg:"ET TROJAN Linux/dtool IRC Command (UDPFLOOD)"; flow:established,from_server; content:"PRIVMSG"; content:"{UDPFLOOD}"; fast_pattern; nocase; content:"Started sending udp data to host"; reference:url,kernel.......4.......x..T.o.G...%.Hm9.qh...J.)?..8.Z......X.!HXJ'.o.!.3.....UB...K.=p..@=p.X....z..Co.....Gf.....T..+.v....}..y......_....I&amp;lt;u..B......I"q......H......3....d..&amp;lt;{.Y.pb......~8...........u.842..o...u....0(.7Z3T...A.#...SC!P2...f4.&amp;gt;..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;.^2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;.T..m.Nn...F..i..9.H..f:....9..[..`a63f...tv,^He....q.....s.4...eh.....|....8GY&amp;amp;5..6gs..uH.6..=..U*.(3..M7...^*......n.;.....!*...p...Ji.R...].:.'J....J..o..t........B..\.wf|#e..kE(.(....z..T^]]... B...M.f.u..I..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;..../....K+..G.L..`.t0T....c3..!...RI...F.F=.....t.?W........?P.........}..t....?._|..9x..9.....'.\7p..J....v....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;......a...5./.........}.j..q...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;.;..G..*.j&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;....P..U%..F..C...s.e.E..U.LE.4.r.7.u.4. @...T[.l_....R&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;any ideas?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 20:32:56 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/alienvault-ossim-alerts-on-netapp-storage/m-p/120047#M25728</guid>
      <dc:creator>minche</dc:creator>
      <dc:date>2025-06-04T20:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: alienvault ossim alerts on netapp storage</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/alienvault-ossim-alerts-on-netapp-storage/m-p/120406#M25794</link>
      <description>&lt;P&gt;u might need to open a case about it&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 04:21:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/alienvault-ossim-alerts-on-netapp-storage/m-p/120406#M25794</guid>
      <dc:creator>Jeff_Yao</dc:creator>
      <dc:date>2016-06-21T04:21:51Z</dc:date>
    </item>
  </channel>
</rss>

