karl
(Karl)
November 12, 2020, 4:11pm
1
Hi,
Is there a document anywhere that show which “sid:prefix” maps to which source or vendor? I have seen https://doc.emergingthreats.net/bin/view/Main/SidAllocation
Ideally i’m looking for “sid:123” is “source X”. Then the range sid:456 to sid:789 is source Y. Is there a table to document this anywhere?
How do different rule authors avoid conflicts?
ish
(Jason Ish)
November 12, 2020, 4:14pm
2
I think thats the only document at this time. But stay tuned, we’ve just been talking about adding the SID ranges to our rule index, which could then provide a mapping like this.
karl
(Karl)
November 12, 2020, 4:20pm
3
Thanks for the quick response. Yes having it in the rule index would be great!