Specifications

Dragon has four default notification rules: netsight−atlas−asm−attacks, netsight−atlas−asm−compromise,
netsight−atlas−asm−informational, and netsight−atlas−asm−misuse. Each of Dragon's notification rules has a
corresponding event category in ASM: ASM_ATTACKS, ASM_COMPROMISE,
ASM_INFORMATIONAL, and ASM_MISUSE.
For ASM's response to a serious threat to be timely and effective, it is important that ASM only be notified of
serious threats. The following table lists the Dragon events for which notification to ASM is recommended:
BACKDOOR:PHATBOT COMP:MS−DIR COMP:ROOT−ICMP
COMP:ROOT−TCP COMP:ROOT−UDP COMP:SDBOT−LOGIN
COMP:SDBOT−NETINFO COMP:SPYBOT−DOWNLOAD COMP:SPYBOT−INFO
COMP:SPYBOT−KEYLOG COMP:WIN−2000 COMP:WIN−XP
GENERIC:UPX−EXE MS−BACKDOOR MS−BACKDOOR2
Automated Security Manager Help
Event Categories 98