side to check: <any|src|dst|both>
-category: the category short name
+``category``: the category short name
-operator: <, >, =
+``operator``: <, <=, >, >=, =
-reputation score: 0-127
+``reputation score``: 0-127
Example:
::
-
alert ip $HOME_NET any -> any any (msg:"IPREP internal host talking to CnC server"; flow:to_server; iprep:dst,CnC,>,30; sid:1; rev:1;)
This rule will alert when a system in $HOME_NET acts as a client while communicating with any IP in the CnC category that has a reputation score set to greater than 30.