Snort Alerts for Day 1 - default rule set


bash-2.05$ grep "\[\*\*\]" alert | sort | uniq -c
      5 [**] [1:0:0] IDS177/netbios_netbios-name-query [**]
      1 [**] [1:0:0] IDS353/shellcode_shellcode-NOOP-Solaris-tcp [**]
33 [**] [1:0:0] IDS545/rpc_rpc_tcp_traffic_contains_bin_sh [**]
   3384 [**] [1:1855:2] DDOS Stacheldraht agent->handler (skillz) [**]
      9 [**] [1:384:4] ICMP PING [**]
      5 [**] [1:402:4] ICMP Destination Unreachable (Port Unreachable) [**]
    402 [**] [1:480:2] ICMP PING speedera [**]
      2 [**] [1:615:3] SCAN SOCKS Proxy attempt [**]
      8 [**] [1:618:2] SCAN Squid Proxy attempt [**]
      8 [**] [1:620:2] SCAN Proxy (8080) attempt [**]