|
Help with rules to detect TLS/HTTPS traffic that is using untrusted CA
|
|
3
|
450
|
November 4, 2024
|
|
LUA script for detecting self-signed certificates cannot load
|
|
0
|
75
|
October 29, 2024
|
|
Require some example for from_base64 keyword
|
|
5
|
161
|
October 28, 2024
|
|
Suricata 7 large file transfer alert
|
|
4
|
219
|
October 26, 2024
|
|
Categorizing rules related to usecases
|
|
1
|
84
|
October 21, 2024
|
|
Creating a custom suricata rule
|
|
11
|
503
|
October 18, 2024
|
|
Can you force UDP packet to be parsed as UDP-ESP instead?
|
|
1
|
44
|
October 13, 2024
|
|
Allow domain and all subdomains/redirects
|
|
3
|
212
|
September 24, 2024
|
|
Can Suricata track TCP sessions
|
|
4
|
117
|
August 30, 2024
|
|
What triggers event.type as dns?
|
|
3
|
81
|
August 29, 2024
|
|
Signature for dropping TCP RST attack
|
|
4
|
274
|
August 20, 2024
|
|
What is the purpose of Suricata rules which have sid 2200000-2299999?
|
|
4
|
194
|
August 7, 2024
|
|
Is there any way in a rule to match a packet marked by iptables?
|
|
1
|
228
|
July 31, 2024
|
|
Filesize keyword suricata
|
|
1
|
139
|
July 31, 2024
|
|
Suricata-update - Error -- Dataset file was not found
|
|
2
|
139
|
July 31, 2024
|
|
Use case of elk using suricata
|
|
1
|
182
|
July 31, 2024
|
|
Suricata protocol DCERPC cannot trigger alert when adding new rule
|
|
3
|
119
|
July 31, 2024
|
|
Found duplicate rule SID XXXX with same revision, keeping the first rule seen
|
|
1
|
263
|
July 26, 2024
|
|
Suricata Rule to monitor all the HTTPS Request with dest port 443
|
|
3
|
346
|
July 17, 2024
|
|
Other sources of rules?
|
|
5
|
902
|
July 13, 2024
|
|
Warning: detect-flowbits: flowbit is checked but not set
|
|
1
|
2191
|
July 9, 2024
|
|
Impossible to install suricata-update from repo github
|
|
17
|
436
|
July 7, 2024
|
|
Does suricata provides attacks/alerts with its counters?
|
|
4
|
145
|
July 1, 2024
|
|
Suricata SID-Descriptions-ETOpen.json
|
|
3
|
242
|
June 26, 2024
|
|
Tls_state keyword unsupported
|
|
3
|
148
|
June 20, 2024
|
|
Unable require scripts in lua
|
|
4
|
191
|
June 8, 2024
|
|
MySQL dictionary attack rule
|
|
2
|
169
|
June 6, 2024
|
|
Parsing errors related to rule keywords associated to DNS protocol
|
|
1
|
140
|
June 3, 2024
|
|
NMAP detection rules for Suricata in GitHub
|
|
6
|
2310
|
May 26, 2024
|
|
Need help understanding the meaning of the content and/or pcre of these two SID rules?
|
|
2
|
240
|
May 24, 2024
|