How to quarantine specific signatures?
Posted: 06 Apr 2015, 16:55
Hi folks,
Quarantine works well enough against the clamav stuff, though question.
If I know a hacker is uploading a particular script, like one with this text I've added to extras now:
regall:POST\[\'veio\'\]
Is there a way to tell quarantine to auto quarantine files with "my" specific signatures as well?
Something like an Other Files -> etc/cxs/cxs.autoquarantine
option would sure be nice. Your thoughts?
Thanks!
Quarantine works well enough against the clamav stuff, though question.
If I know a hacker is uploading a particular script, like one with this text I've added to extras now:
regall:POST\[\'veio\'\]
Is there a way to tell quarantine to auto quarantine files with "my" specific signatures as well?
Something like an Other Files -> etc/cxs/cxs.autoquarantine
option would sure be nice. Your thoughts?
Thanks!