FireEye - Custom SNORT rules are enabled

Information

FireEye Web MPS supports the use of custom rules for malware analysis. It allows end users to load their own format signature rules which will cause the FireEye appliance to detect customer specific traffic patterns and generate alerts.

Solution

Edit the configuration and modify this line:\n

fenet security-content custom rule enable

Item Details

Audit Name: TNS FireEye

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4

Plugin: FireEye

Control ID: 6613f253dd793486a414eb08f2fb7e493d6e6651729a3792ce545c4752b23fcb