Re: [tor-talk] What is being detected to alert upon?

On Thu, Apr 30, 2015 at 02:57:01PM -0400, tor@xxxxxxx wrote:
> One rules file is dedicated to it (emerging-tor.rules), that file has all
> the Tor IP addresses hardcoded into it.

That's probably not very effective because the Tor network has quite a
bit of churn, which would lead to plenty of false positives and false
negatives.  You would have to update this list pretty much hourly.

