Is there a generic way in suricata to match on stuff from a file? It’s possible for IPs and FQDNs as far as I know.
I have multiple files containing indicators, as follows:
How do I get alerted on domains from a file, matching on a field (eg: dns_query) with any subdomain? For example if I have google.com listed in the file, can I get alerts on images.google.com in dns_query field?
Example file domains.txt would contain:
Same for domains above, but for URLs or URIs. How do I get alerted on them in HTTP traffic for example?
Example file urls.txt would contain:
Any guidance is appreciated. Thanks a lot for your help.