}
# OPTIONAL: Advanced pattern matching
- # Uncomment to enable custom user field patterns
- # pattern_map = "$LOCAL_CONFDIR/local.d/url_suspect_user_patterns.map";
+ # To enable, add in local.d/url_suspect.conf:
+ # pattern_map = "$LOCAL_CONFDIR/local.d/maps/url_suspect_user_patterns.map";
# OPTIONAL: User blacklist
- # Uncomment to enable user field blacklist
- # blacklist_map = "$LOCAL_CONFDIR/local.d/url_suspect_user_blacklist.map";
+ # To enable, add in local.d/url_suspect.conf:
+ # blacklist_map = "$LOCAL_CONFDIR/local.d/maps/url_suspect_user_blacklist.map";
}
# Numeric IP address analysis
private_score = 0.5; # Lower score for private IPs
# OPTIONAL: Suspicious IP ranges map
- # Uncomment to enable custom IP range checking
- # range_map = "$LOCAL_CONFDIR/local.d/url_suspect_ip_ranges.map";
+ # To enable, add in local.d/url_suspect.conf:
+ # range_map = "$LOCAL_CONFDIR/local.d/maps/url_suspect_ip_ranges.map";
}
# TLD (Top Level Domain) analysis
missing_tld_score = 2.0;
# OPTIONAL: Custom TLD map
- # Uncomment to add additional TLDs to check
- # tld_map = "$LOCAL_CONFDIR/local.d/url_suspect_tlds.map";
+ # To enable, add in local.d/url_suspect.conf:
+ # tld_map = "$LOCAL_CONFDIR/local.d/maps/url_suspect_tlds.map";
}
# Unicode and encoding analysis
max_url_length = 2048;
# OPTIONAL: Suspicious ports map
- # Uncomment to check for unusual ports
- # port_map = "$LOCAL_CONFDIR/local.d/url_suspect_ports.map";
+ # To enable, add in local.d/url_suspect.conf:
+ # port_map = "$LOCAL_CONFDIR/local.d/maps/url_suspect_ports.map";
}
}
}
# ADVANCED: Global whitelist
- # Uncomment to skip checks for specific domains
- # whitelist_map = "$LOCAL_CONFDIR/local.d/url_suspect_whitelist.map";
+ # To enable, add in local.d/url_suspect.conf:
+ # whitelist_map = "$LOCAL_CONFDIR/local.d/maps/url_suspect_whitelist.map";
- # ADVANCED: Custom checks (disabled by default)
- # Example:
+ # ADVANCED: Custom checks
+ # To enable, add in local.d/url_suspect.conf:
# custom_checks {
# my_check = <<EOD
# return function(task, url, settings)