pulledpork
pulledpork copied to clipboard
Add a feature to only update sid-msg.map, mainly for local rule modifications.
From da_667 on IRC:
Quick question for ya: How would one run pulledpork to update JUST the sid-msg.map? So my use case: add local rules update sid-msg.map and that's it
Isn't there an option to just run locally? Instead of downloading the Ruleset. I want to say it's -k
I will take a look, if anything, the function and documentation for -k|-K needs to be updated.
It's -n sorry,
-n appears to process a local rules file(snort-subscriber.tar.gz). I will check with DA, but I thought he just wants to grab the local.rules file defined in his Snort instance and update sid-msg.map to reflect any 'local.rule' file changes.
I think that's exactly what that function should do.