Help with rules to detect TLS/HTTPS traffic that is using untrusted CA
|
|
3
|
177
|
November 4, 2024
|
LUA script for detecting self-signed certificates cannot load
|
|
0
|
35
|
October 29, 2024
|
Require some example for from_base64 keyword
|
|
5
|
68
|
October 28, 2024
|
Suricata 7 large file transfer alert
|
|
4
|
83
|
October 26, 2024
|
Categorizing rules related to usecases
|
|
1
|
41
|
October 21, 2024
|
Creating a custom suricata rule
|
|
11
|
218
|
October 18, 2024
|
Can you force UDP packet to be parsed as UDP-ESP instead?
|
|
1
|
22
|
October 13, 2024
|
Allow domain and all subdomains/redirects
|
|
3
|
136
|
September 24, 2024
|
Can Suricata track TCP sessions
|
|
4
|
74
|
August 30, 2024
|
What triggers event.type as dns?
|
|
3
|
39
|
August 29, 2024
|
Signature for dropping TCP RST attack
|
|
4
|
143
|
August 20, 2024
|
What is the purpose of Suricata rules which have sid 2200000-2299999?
|
|
4
|
109
|
August 7, 2024
|
Is there any way in a rule to match a packet marked by iptables?
|
|
1
|
167
|
July 31, 2024
|
Filesize keyword suricata
|
|
1
|
103
|
July 31, 2024
|
Suricata-update - Error -- Dataset file was not found
|
|
2
|
104
|
July 31, 2024
|
Use case of elk using suricata
|
|
1
|
162
|
July 31, 2024
|
Suricata protocol DCERPC cannot trigger alert when adding new rule
|
|
3
|
54
|
July 31, 2024
|
Found duplicate rule SID XXXX with same revision, keeping the first rule seen
|
|
1
|
126
|
July 26, 2024
|
Suricata Rule to monitor all the HTTPS Request with dest port 443
|
|
3
|
146
|
July 17, 2024
|
Other sources of rules?
|
|
5
|
467
|
July 13, 2024
|
Warning: detect-flowbits: flowbit is checked but not set
|
|
1
|
1021
|
July 9, 2024
|
Impossible to install suricata-update from repo github
|
|
17
|
197
|
July 7, 2024
|
Does suricata provides attacks/alerts with its counters?
|
|
4
|
118
|
July 1, 2024
|
Suricata SID-Descriptions-ETOpen.json
|
|
3
|
112
|
June 26, 2024
|
Tls_state keyword unsupported
|
|
3
|
114
|
June 20, 2024
|
Unable require scripts in lua
|
|
4
|
157
|
June 8, 2024
|
MySQL dictionary attack rule
|
|
2
|
124
|
June 6, 2024
|
Parsing errors related to rule keywords associated to DNS protocol
|
|
1
|
106
|
June 3, 2024
|
NMAP detection rules for Suricata in GitHub
|
|
6
|
1284
|
May 26, 2024
|
Need help understanding the meaning of the content and/or pcre of these two SID rules?
|
|
2
|
154
|
May 24, 2024
|