You might need to flesh out the rules for asterisk.  I didn't see anything 
based on INVITE in the asterisk section of the decodes or the built-in 
rules.  

Sometimes it's necessary to add what you want to watch for in the 
local_rules.xml - it shouldn't be too tough to add a <match></match> for 
what you're looking for.

On Monday, March 9, 2015 at 10:04:02 AM UTC-7, Van Nistelroot wrote:
>
> Hi list, 
>
> When you attack PBX by enumerating users, you can do it via INVITE, 
> REGISTER and OPTIONS. 
>
> ossec is only able to detect REGISTER requests, but nothing happens 
> when successfully  try to enumerate vía INVITE ( tried myself ) 
>
> I´m doing something wrong or ossec has to be tweaked? 
>
> Kind Regards, 
>
> Daniel 
>

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to