diff options
author | Vsevolod Stakhov <vsevolod@highsecure.ru> | 2019-11-27 14:53:27 +0000 |
---|---|---|
committer | Vsevolod Stakhov <vsevolod@highsecure.ru> | 2019-11-27 14:53:27 +0000 |
commit | 17d100afebda176346bb7f929507a9eab49b6678 (patch) | |
tree | cd2338a9e37e8265cabe5624094a319a2183f6ff /conf/scores.d | |
parent | dcb3a9cfac9d0c9f1024c2ee90cd12ed1583e892 (diff) | |
download | rspamd-17d100afebda176346bb7f929507a9eab49b6678.tar.gz rspamd-17d100afebda176346bb7f929507a9eab49b6678.zip |
[Rules] Add PDF related rules
Diffstat (limited to 'conf/scores.d')
-rw-r--r-- | conf/scores.d/content_group.conf | 37 |
1 files changed, 37 insertions, 0 deletions
diff --git a/conf/scores.d/content_group.conf b/conf/scores.d/content_group.conf new file mode 100644 index 000000000..b53ec31d0 --- /dev/null +++ b/conf/scores.d/content_group.conf @@ -0,0 +1,37 @@ +# Content matching rules +# +# Please don't modify this file as your changes might be overwritten with +# the next update. +# +# You can modify '$LOCAL_CONFDIR/rspamd.conf.local.override' to redefine +# parameters defined on the top level +# +# You can modify '$LOCAL_CONFDIR/rspamd.conf.local' to add +# parameters defined on the top level +# +# For specific modules or configuration you can also modify +# '$LOCAL_CONFDIR/local.d/file.conf' - to add your options or rewrite defaults +# '$LOCAL_CONFDIR/override.d/file.conf' - to override the defaults +# +# See https://rspamd.com/doc/tutorials/writing_rules.html for details + +description = "Content rules"; + +symbols = { + "PDF_ENCRYPTED" { + weight = 0.3; + description = "There is an encrypted PDF in the message"; + one_shot = true; + } + "PDF_JAVASCRIPT" { + weight = 0.1; + description = "There is an PDF with JavaScript in the message"; + one_shot = true; + } + "PDF_SUSPICIOUS" { + weight = 4.5; + description = "There is an PDF with suspicious properties in the message"; + one_shot = true; + } +} + |