[Snort-users] acid, sig_priority
cmg at ...671...
Tue Dec 2 18:11:01 EST 2003
Nicholas Bernstein <nick at ...10668...> writes:
> Could someone tell me what exactly sig_priority does? Is it a general
> threat level? i.e remote root could be 5 where info gathering might be
> 1? Am I way off?
It's supposed to be. It's not that useful currently ( and never has
been ). Preprocessors generally use 5 and rules use 1-3. Look at
classification.config for what is high/low.
Chris Green <cmg at ...1121...>
"I'm beginning to think that my router may be confused."
More information about the Snort-users