You might need to flesh out the rules for asterisk. I didn't see anything based on INVITE in the asterisk section of the decodes or the built-in rules.
Sometimes it's necessary to add what you want to watch for in the local_rules.xml - it shouldn't be too tough to add a <match></match> for what you're looking for. On Monday, March 9, 2015 at 10:04:02 AM UTC-7, Van Nistelroot wrote: > > Hi list, > > When you attack PBX by enumerating users, you can do it via INVITE, > REGISTER and OPTIONS. > > ossec is only able to detect REGISTER requests, but nothing happens > when successfully try to enumerate vía INVITE ( tried myself ) > > I´m doing something wrong or ossec has to be tweaked? > > Kind Regards, > > Daniel > -- --- You received this message because you are subscribed to the Google Groups "ossec-list" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
