$HOME_NET in suricata rule ignored?



Created some custom rules I borrowed from ET, but is seems like the destination variable $HOME_NET is ignored? Maybe a second pair of eyes can share some insight?

alert tcp $HOME_NET any → $HOME_NET any (msg:“SCAN NMAP -sA (1)”; fragbits:!D; dsize:0; flags:A,12; window:1024; threshold: type both, track by_dst, count 1, seconds 60; reference:url,Emerging Threats; classtype:attempted-recon; sid:100000022; rev:8; metadata:created_at 2010_07_30, updated_at 2010_07_30;)

It also hits on destination ip’s way out of the HOME_NET scope defined in suricata.yaml (suricata 7).


Does it work if you change it to any instead of HOME_NET?
And if so, did you double check the IPs are in the HOME_NET variable?

tnx for your reply Andreas, but it was a combination of different event types (alert, protocols) which led to my confusion.