19/1/2022 -- 15:10:15 - - This is Suricata version 6.0.3 RELEASE running in SYSTEM mode 19/1/2022 -- 15:10:15 - - CPUs/cores online: 8 19/1/2022 -- 15:10:15 - - Found an MTU of 1500 for '\Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}' 19/1/2022 -- 15:10:15 - - Found an MTU of 1500 for '\Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}' 19/1/2022 -- 15:10:15 - - Configuring core dump is not yet supported on Windows. 19/1/2022 -- 15:10:15 - - Shortening device name to: \Dev..472} 19/1/2022 -- 15:10:15 - - fast output device (regular) initialized: fast.log 19/1/2022 -- 15:10:15 - - eve-log output device (regular) initialized: eve.json 19/1/2022 -- 15:10:15 - - stats output device (regular) initialized: stats.log 19/1/2022 -- 15:10:16 - - 44 rule files processed. 23850 rules successfully loaded, 0 rules failed 19/1/2022 -- 15:10:16 - - Threshold config parsed: 0 rule(s) found 19/1/2022 -- 15:10:16 - - 23853 signatures processed. 1289 are IP-only rules, 4139 are inspecting packet payload, 18400 inspect application layer, 0 are decoder event only 19/1/2022 -- 15:10:26 - - Using 1 live device(s). 19/1/2022 -- 15:10:26 - - using interface \Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472} 19/1/2022 -- 15:10:26 - - running in 'auto' checksum mode. Detection of interface state will require 1000ULL packets 19/1/2022 -- 15:10:26 - - Found an MTU of 1500 for '\Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}' 19/1/2022 -- 15:10:26 - - Set snaplen to 1524 for '\Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}' 19/1/2022 -- 15:10:26 - - [ERRCODE: SC_ERR_NIC_OFFLOADING(284)] - NIC offloading on \Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}: Checksum IPv4 Rx: 1 Tx: 1 IPv6 Rx: 1 Tx: 1 LSOv1 IPv4: 0 LSOv2 IPv4: 1 IPv6: 1 19/1/2022 -- 15:10:26 - - RunModeIdsPcapAutoFp initialised 19/1/2022 -- 15:10:26 - - all 9 packet processing threads, 4 management threads initialized, engine started. 19/1/2022 -- 15:14:36 - - This is Suricata version 6.0.3 RELEASE running in SYSTEM mode 19/1/2022 -- 15:14:36 - - CPUs/cores online: 8 19/1/2022 -- 15:14:36 - - Found an MTU of 1500 for '\Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}' 19/1/2022 -- 15:14:36 - - Found an MTU of 1500 for '\Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}' 19/1/2022 -- 15:14:36 - - Configuring core dump is not yet supported on Windows. 19/1/2022 -- 15:14:36 - - Shortening device name to: \Dev..472} 19/1/2022 -- 15:14:36 - - fast output device (regular) initialized: fast.log 19/1/2022 -- 15:14:36 - - eve-log output device (regular) initialized: eve.json 19/1/2022 -- 15:14:36 - - stats output device (regular) initialized: stats.log 19/1/2022 -- 15:14:37 - - 44 rule files processed. 23850 rules successfully loaded, 0 rules failed 19/1/2022 -- 15:14:37 - - Threshold config parsed: 0 rule(s) found 19/1/2022 -- 15:14:37 - - 23853 signatures processed. 1289 are IP-only rules, 4139 are inspecting packet payload, 18400 inspect application layer, 0 are decoder event only 19/1/2022 -- 15:14:46 - - Using 1 live device(s). 19/1/2022 -- 15:14:46 - - using interface \Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472} 19/1/2022 -- 15:14:46 - - running in 'auto' checksum mode. Detection of interface state will require 1000ULL packets 19/1/2022 -- 15:14:46 - - Found an MTU of 1500 for '\Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}' 19/1/2022 -- 15:14:46 - - Set snaplen to 1524 for '\Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}' 19/1/2022 -- 15:14:46 - - [ERRCODE: SC_ERR_NIC_OFFLOADING(284)] - NIC offloading on \Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}: Checksum IPv4 Rx: 1 Tx: 1 IPv6 Rx: 1 Tx: 1 LSOv1 IPv4: 0 LSOv2 IPv4: 1 IPv6: 1 19/1/2022 -- 15:14:47 - - RunModeIdsPcapAutoFp initialised 19/1/2022 -- 15:14:47 - - all 9 packet processing threads, 4 management threads initialized, engine started. 19/1/2022 -- 15:16:14 - - Signal Received. Stopping engine. 19/1/2022 -- 15:16:14 - - time elapsed 87.752s 19/1/2022 -- 15:16:14 - - (RX#01-\Dev..472) Packets 314, bytes 59752 19/1/2022 -- 15:16:14 - - (RX#01-\Dev..472) Pcap Total:317 Recv:317 Drop:0 (0.0%). 19/1/2022 -- 15:16:14 - - Alerts: 0 19/1/2022 -- 15:16:15 - - cleaning up signature grouping structure... complete 19/1/2022 -- 15:16:15 - - Stats for '\Device\NPF_{750ADE9E-7210-46A9-B4F0-60571C5BB472}': pkts: 314, drop: 0 (0.00%), invalid chksum: 98 19/1/2022 -- 15:16:22 - - This is Suricata version 6.0.3 RELEASE running in SYSTEM mode 19/1/2022 -- 15:16:22 - - CPUs/cores online: 8 19/1/2022 -- 15:16:22 - - 'default' server has 'request-body-minimal-inspect-size' set to 31390 and 'request-body-inspect-window' set to 3910 after randomization. 19/1/2022 -- 15:16:22 - - 'default' server has 'response-body-minimal-inspect-size' set to 42534 and 'response-body-inspect-window' set to 16804 after randomization. 19/1/2022 -- 15:16:22 - - SMB stream depth: 0 19/1/2022 -- 15:16:22 - - Protocol detection and parser disabled for modbus protocol. 19/1/2022 -- 15:16:22 - - Protocol detection and parser disabled for enip protocol. 19/1/2022 -- 15:16:22 - - Protocol detection and parser disabled for DNP3. 19/1/2022 -- 15:16:22 - - Found a global MTU of 1500 19/1/2022 -- 15:16:22 - - allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64 19/1/2022 -- 15:16:22 - - preallocated 1000 hosts of size 104 19/1/2022 -- 15:16:22 - - host memory usage: 366144 bytes, maximum: 33554432 19/1/2022 -- 15:16:22 - - Configuring core dump is not yet supported on Windows. 19/1/2022 -- 15:16:22 - - allocated 1572864 bytes of memory for the defrag hash... 65536 buckets of size 24 19/1/2022 -- 15:16:22 - - preallocated 65535 defrag trackers of size 120 19/1/2022 -- 15:16:22 - - defrag memory usage: 9437064 bytes, maximum: 33554432 19/1/2022 -- 15:16:23 - - flow size 264, memcap allows for 508400 flows. Per hash row in perfect conditions 7 19/1/2022 -- 15:16:23 - - stream "prealloc-sessions": 2048 (per thread) 19/1/2022 -- 15:16:23 - - stream "memcap": 67108864 19/1/2022 -- 15:16:23 - - stream "midstream" session pickups: disabled 19/1/2022 -- 15:16:23 - - stream "async-oneside": disabled 19/1/2022 -- 15:16:23 - - stream "checksum-validation": disabled 19/1/2022 -- 15:16:23 - - stream."inline": disabled 19/1/2022 -- 15:16:23 - - stream "bypass": disabled 19/1/2022 -- 15:16:23 - - stream "max-synack-queued": 5 19/1/2022 -- 15:16:23 - - stream.reassembly "memcap": 268435456 19/1/2022 -- 15:16:23 - - stream.reassembly "depth": 1048576 19/1/2022 -- 15:16:23 - - stream.reassembly "toserver-chunk-size": 2666 19/1/2022 -- 15:16:23 - - stream.reassembly "toclient-chunk-size": 2477 19/1/2022 -- 15:16:23 - - stream.reassembly.raw: enabled 19/1/2022 -- 15:16:23 - - stream.reassembly "segment-prealloc": 2048 19/1/2022 -- 15:16:23 - - fast output device (regular) initialized: fast.log 19/1/2022 -- 15:16:23 - - eve-log output device (regular) initialized: eve.json 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'alert' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'anomaly' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'http' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'dns' 19/1/2022 -- 15:16:23 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:16:23 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'tls' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'files' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'smtp' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'ftp' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'rdp' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'nfs' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'smb' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'tftp' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'ikev2' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'dcerpc' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'krb5' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'snmp' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'rfb' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'sip' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'dhcp' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'ssh' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'mqtt' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'stats' 19/1/2022 -- 15:16:23 - - enabling 'eve-log' module 'flow' 19/1/2022 -- 15:16:23 - - stats output device (regular) initialized: stats.log 19/1/2022 -- 15:16:23 - - Delayed detect disabled 19/1/2022 -- 15:16:23 - - pattern matchers: MPM: ac, SPM: bm 19/1/2022 -- 15:16:23 - - grouping: tcp-whitelist (default) 53, 80, 139, 443, 445, 1433, 3306, 3389, 6666, 6667, 8080 19/1/2022 -- 15:16:23 - - grouping: udp-whitelist (default) 53, 135, 5060 19/1/2022 -- 15:16:23 - - prefilter engines: MPM 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_request_line 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_client_body 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_response_line 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:16:23 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_host 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_stat_msg 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for dns_query 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for tls.sni 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for tls.cert_issuer 19/1/2022 -- 15:16:24 - - using shared mpm ctx' for tls.cert_subject 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for tls.cert_serial 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for tls.cert_fingerprint 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for tls.certs 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ja3.hash 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ja3.string 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ja3s.hash 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ja3s.string 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for smb_named_pipe 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for smb_share 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ssh.hassh 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ssh.hassh.server 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ssh.hassh.string 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for ssh.hassh.server.string 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for krb5_cname 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for krb5_sname 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for sip.uri 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for sip.stat_msg 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for sip.request_line 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for sip.response_line 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for rfb.name 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for mqtt.connect.clientid 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for mqtt.connect.username 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for mqtt.connect.password 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for mqtt.connect.willtopic 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for mqtt.connect.willmessage 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for mqtt.publish.topic 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for mqtt.publish.message 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for mqtt.subscribe.topic 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for mqtt.unsubscribe.topic 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for icmpv4.hdr 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for tcp.hdr 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for udp.hdr 19/1/2022 -- 15:16:25 - - using shared mpm ctx' for icmpv6.hdr 19/1/2022 -- 15:16:26 - - using shared mpm ctx' for ipv4.hdr 19/1/2022 -- 15:16:26 - - using shared mpm ctx' for ipv6.hdr 19/1/2022 -- 15:16:26 - - IP reputation disabled 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\botcc.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\botcc.portgrouped.rules 19/1/2022 -- 15:16:26 - - No rules loaded from botcc.portgrouped.rules. 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\ciarmy.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\compromised.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\drop.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\dshield.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-activex.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-attack_response.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-chat.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-current_events.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-dns.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-dos.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-exploit.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-ftp.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-games.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-icmp_info.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-icmp.rules 19/1/2022 -- 15:16:26 - - No rules loaded from emerging-icmp.rules. 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-imap.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-inappropriate.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-info.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-malware.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-misc.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-mobile_malware.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-netbios.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-p2p.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-policy.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-pop3.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-rpc.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-scada.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-scan.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-shellcode.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-smtp.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-snmp.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-sql.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-telnet.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-tftp.rules 19/1/2022 -- 15:16:26 - - Loading rule file: C:\Suricata\rules\emerging-trojan.rules 19/1/2022 -- 15:16:27 - - Loading rule file: C:\Suricata\rules\emerging-user_agents.rules 19/1/2022 -- 15:16:27 - - Loading rule file: C:\Suricata\rules\emerging-voip.rules 19/1/2022 -- 15:16:27 - - Loading rule file: C:\Suricata\rules\emerging-web_client.rules 19/1/2022 -- 15:16:27 - - Loading rule file: C:\Suricata\rules\emerging-web_server.rules 19/1/2022 -- 15:16:27 - - Loading rule file: C:\Suricata\rules\emerging-web_specific_apps.rules 19/1/2022 -- 15:16:27 - - Loading rule file: C:\Suricata\rules\emerging-worm.rules 19/1/2022 -- 15:16:27 - - Loading rule file: C:\Suricata\rules\tor.rules 19/1/2022 -- 15:16:27 - - 44 rule files processed. 23850 rules successfully loaded, 0 rules failed 19/1/2022 -- 15:16:27 - - Threshold config parsed: 0 rule(s) found 19/1/2022 -- 15:16:27 - - using shared mpm ctx' for tcp-packet 19/1/2022 -- 15:16:27 - - using shared mpm ctx' for tcp-stream 19/1/2022 -- 15:16:27 - - using shared mpm ctx' for udp-packet 19/1/2022 -- 15:16:27 - - using shared mpm ctx' for other-ip 19/1/2022 -- 15:16:27 - - 23853 signatures processed. 1289 are IP-only rules, 4139 are inspecting packet payload, 18400 inspect application layer, 0 are decoder event only 19/1/2022 -- 15:16:27 - - building signature grouping structure, stage 1: preprocessing rules... complete 19/1/2022 -- 15:16:27 - - TCP toserver: 41 port groups, 39 unique SGH's, 2 copies 19/1/2022 -- 15:16:27 - - TCP toclient: 21 port groups, 21 unique SGH's, 0 copies 19/1/2022 -- 15:16:27 - - UDP toserver: 41 port groups, 38 unique SGH's, 3 copies 19/1/2022 -- 15:16:27 - - UDP toclient: 21 port groups, 17 unique SGH's, 4 copies 19/1/2022 -- 15:16:27 - - OTHER toserver: 254 proto groups, 3 unique SGH's, 251 copies 19/1/2022 -- 15:16:27 - - OTHER toclient: 254 proto groups, 0 unique SGH's, 254 copies 19/1/2022 -- 15:16:36 - - Unique rule groups: 118 19/1/2022 -- 15:16:36 - - Builtin MPM "toserver TCP packet": 26 19/1/2022 -- 15:16:36 - - Builtin MPM "toclient TCP packet": 20 19/1/2022 -- 15:16:36 - - Builtin MPM "toserver TCP stream": 30 19/1/2022 -- 15:16:36 - - Builtin MPM "toclient TCP stream": 21 19/1/2022 -- 15:16:36 - - Builtin MPM "toserver UDP packet": 38 19/1/2022 -- 15:16:36 - - Builtin MPM "toclient UDP packet": 16 19/1/2022 -- 15:16:36 - - Builtin MPM "other IP packet": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_uri (http)": 8 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_uri (http2)": 8 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_raw_uri (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_raw_uri (http2)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_request_line (http)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_client_body (http)": 5 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_response_line (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_header (http)": 8 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_header (http)": 8 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_header_names (http)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_header_names (http)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_accept (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_accept (http2)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_accept_enc (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_accept_enc (http2)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_accept_lang (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_accept_lang (http2)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_referer (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_referer (http2)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_content_len (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_content_len (http2)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_content_len (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_content_len (http2)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_content_type (http)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_content_type (http2)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_content_type (http)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_content_type (http2)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_protocol (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_protocol (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_start (http)": 4 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_start (http)": 4 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_raw_header (http)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_raw_header (http)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_method (http)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_method (http2)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_cookie (http)": 3 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_cookie (http)": 3 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_cookie (http2)": 3 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_cookie (http2)": 3 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_user_agent (http)": 6 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_user_agent (http2)": 6 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_host (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_raw_host (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver http_raw_host (http2)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_stat_code (http)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient http_stat_code (http2)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver dns_query (dns)": 4 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver tls.sni (tls)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient tls.cert_issuer (tls)": 5 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient tls.cert_subject (tls)": 2 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient tls.cert_serial (tls)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toserver ssh.proto (ssh)": 1 19/1/2022 -- 15:16:36 - - AppLayer MPM "toclient ssh.proto (ssh)": 1 19/1/2022 -- 15:16:37 - - AppLayer MPM "toserver file_data (smtp)": 7 19/1/2022 -- 15:16:37 - - AppLayer MPM "toclient file_data (http)": 7 19/1/2022 -- 15:16:37 - - AppLayer MPM "toserver file_data (smb)": 7 19/1/2022 -- 15:16:37 - - AppLayer MPM "toclient file_data (smb)": 7 19/1/2022 -- 15:16:37 - - AppLayer MPM "toserver file_data (http2)": 7 19/1/2022 -- 15:16:37 - - AppLayer MPM "toclient file_data (http2)": 7 19/1/2022 -- 15:16:37 - - AutoFP mode using "Hash" flow load balancer 19/1/2022 -- 15:16:37 - - [ERRCODE: SC_ERR_WINDIVERT_GENERIC(312)] - WinDivertOpen failed, error 5 (0x00000005): Accès refusé. Suricata must be run with Administrator privileges. 19/1/2022 -- 15:16:37 - - using 1 flow manager threads 19/1/2022 -- 15:16:37 - - using 1 flow recycler threads 19/1/2022 -- 15:16:38 - - [ERRCODE: SC_ERR_THREAD_INIT(49)] - thread "RX-1" failed to initialize: flags 0145 19/1/2022 -- 15:16:38 - - [ERRCODE: SC_ERR_FATAL(171)] - Engine initialization failed, aborting... 19/1/2022 -- 15:18:18 - - This is Suricata version 6.0.3 RELEASE running in SYSTEM mode 19/1/2022 -- 15:18:18 - - CPUs/cores online: 8 19/1/2022 -- 15:18:18 - - 'default' server has 'request-body-minimal-inspect-size' set to 31413 and 'request-body-inspect-window' set to 4094 after randomization. 19/1/2022 -- 15:18:18 - - 'default' server has 'response-body-minimal-inspect-size' set to 40674 and 'response-body-inspect-window' set to 16175 after randomization. 19/1/2022 -- 15:18:18 - - SMB stream depth: 0 19/1/2022 -- 15:18:18 - - Protocol detection and parser disabled for modbus protocol. 19/1/2022 -- 15:18:18 - - Protocol detection and parser disabled for enip protocol. 19/1/2022 -- 15:18:18 - - Protocol detection and parser disabled for DNP3. 19/1/2022 -- 15:18:18 - - Found a global MTU of 1500 19/1/2022 -- 15:18:19 - - allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64 19/1/2022 -- 15:18:19 - - preallocated 1000 hosts of size 104 19/1/2022 -- 15:18:19 - - host memory usage: 366144 bytes, maximum: 33554432 19/1/2022 -- 15:18:19 - - Configuring core dump is not yet supported on Windows. 19/1/2022 -- 15:18:19 - - allocated 1572864 bytes of memory for the defrag hash... 65536 buckets of size 24 19/1/2022 -- 15:18:19 - - preallocated 65535 defrag trackers of size 120 19/1/2022 -- 15:18:19 - - defrag memory usage: 9437064 bytes, maximum: 33554432 19/1/2022 -- 15:18:19 - - flow size 264, memcap allows for 508400 flows. Per hash row in perfect conditions 7 19/1/2022 -- 15:18:19 - - stream "prealloc-sessions": 2048 (per thread) 19/1/2022 -- 15:18:19 - - stream "memcap": 67108864 19/1/2022 -- 15:18:19 - - stream "midstream" session pickups: disabled 19/1/2022 -- 15:18:19 - - stream "async-oneside": disabled 19/1/2022 -- 15:18:19 - - stream "checksum-validation": disabled 19/1/2022 -- 15:18:19 - - stream."inline": disabled 19/1/2022 -- 15:18:19 - - stream "bypass": disabled 19/1/2022 -- 15:18:19 - - stream "max-synack-queued": 5 19/1/2022 -- 15:18:19 - - stream.reassembly "memcap": 268435456 19/1/2022 -- 15:18:19 - - stream.reassembly "depth": 1048576 19/1/2022 -- 15:18:19 - - stream.reassembly "toserver-chunk-size": 2472 19/1/2022 -- 15:18:19 - - stream.reassembly "toclient-chunk-size": 2682 19/1/2022 -- 15:18:19 - - stream.reassembly.raw: enabled 19/1/2022 -- 15:18:19 - - stream.reassembly "segment-prealloc": 2048 19/1/2022 -- 15:18:19 - - fast output device (regular) initialized: fast.log 19/1/2022 -- 15:18:19 - - eve-log output device (regular) initialized: eve.json 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'alert' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'anomaly' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'http' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'dns' 19/1/2022 -- 15:18:19 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:18:19 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'tls' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'files' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'smtp' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'ftp' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'rdp' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'nfs' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'smb' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'tftp' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'ikev2' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'dcerpc' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'krb5' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'snmp' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'rfb' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'sip' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'dhcp' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'ssh' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'mqtt' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'stats' 19/1/2022 -- 15:18:19 - - enabling 'eve-log' module 'flow' 19/1/2022 -- 15:18:19 - - stats output device (regular) initialized: stats.log 19/1/2022 -- 15:18:19 - - Delayed detect disabled 19/1/2022 -- 15:18:19 - - pattern matchers: MPM: ac, SPM: bm 19/1/2022 -- 15:18:19 - - grouping: tcp-whitelist (default) 53, 80, 139, 443, 445, 1433, 3306, 3389, 6666, 6667, 8080 19/1/2022 -- 15:18:19 - - grouping: udp-whitelist (default) 53, 135, 5060 19/1/2022 -- 15:18:19 - - prefilter engines: MPM 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_request_line 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_client_body 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_response_line 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_host 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_stat_msg 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for dns_query 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for tls.sni 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for tls.cert_issuer 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for tls.cert_subject 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for tls.cert_serial 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for tls.cert_fingerprint 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for tls.certs 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ja3.hash 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ja3.string 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ja3s.hash 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ja3s.string 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for smb_named_pipe 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for smb_share 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ssh.hassh 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ssh.hassh.server 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ssh.hassh.string 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for ssh.hassh.server.string 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for krb5_cname 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for krb5_sname 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for sip.uri 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for sip.stat_msg 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for sip.request_line 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for sip.response_line 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for rfb.name 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for mqtt.connect.clientid 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for mqtt.connect.username 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for mqtt.connect.password 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for mqtt.connect.willtopic 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for mqtt.connect.willmessage 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for mqtt.publish.topic 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for mqtt.publish.message 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for mqtt.subscribe.topic 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for mqtt.unsubscribe.topic 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for icmpv4.hdr 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for tcp.hdr 19/1/2022 -- 15:18:19 - - using shared mpm ctx' for udp.hdr 19/1/2022 -- 15:18:20 - - using shared mpm ctx' for icmpv6.hdr 19/1/2022 -- 15:18:20 - - using shared mpm ctx' for ipv4.hdr 19/1/2022 -- 15:18:20 - - using shared mpm ctx' for ipv6.hdr 19/1/2022 -- 15:18:20 - - IP reputation disabled 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\botcc.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\botcc.portgrouped.rules 19/1/2022 -- 15:18:20 - - No rules loaded from botcc.portgrouped.rules. 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\ciarmy.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\compromised.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\drop.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\dshield.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-activex.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-attack_response.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-chat.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-current_events.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-dns.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-dos.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-exploit.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-ftp.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-games.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-icmp_info.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-icmp.rules 19/1/2022 -- 15:18:20 - - No rules loaded from emerging-icmp.rules. 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-imap.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-inappropriate.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-info.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-malware.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-misc.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-mobile_malware.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-netbios.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-p2p.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-policy.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-pop3.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-rpc.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-scada.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-scan.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-shellcode.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-smtp.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-snmp.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-sql.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-telnet.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-tftp.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-trojan.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-user_agents.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-voip.rules 19/1/2022 -- 15:18:20 - - Loading rule file: C:\Suricata\rules\emerging-web_client.rules 19/1/2022 -- 15:18:21 - - Loading rule file: C:\Suricata\rules\emerging-web_server.rules 19/1/2022 -- 15:18:21 - - Loading rule file: C:\Suricata\rules\emerging-web_specific_apps.rules 19/1/2022 -- 15:18:21 - - Loading rule file: C:\Suricata\rules\emerging-worm.rules 19/1/2022 -- 15:18:21 - - Loading rule file: C:\Suricata\rules\tor.rules 19/1/2022 -- 15:18:21 - - 44 rule files processed. 23850 rules successfully loaded, 0 rules failed 19/1/2022 -- 15:18:21 - - Threshold config parsed: 0 rule(s) found 19/1/2022 -- 15:18:21 - - using shared mpm ctx' for tcp-packet 19/1/2022 -- 15:18:21 - - using shared mpm ctx' for tcp-stream 19/1/2022 -- 15:18:21 - - using shared mpm ctx' for udp-packet 19/1/2022 -- 15:18:21 - - using shared mpm ctx' for other-ip 19/1/2022 -- 15:18:21 - - 23853 signatures processed. 1289 are IP-only rules, 4139 are inspecting packet payload, 18400 inspect application layer, 0 are decoder event only 19/1/2022 -- 15:18:21 - - building signature grouping structure, stage 1: preprocessing rules... complete 19/1/2022 -- 15:18:21 - - TCP toserver: 41 port groups, 39 unique SGH's, 2 copies 19/1/2022 -- 15:18:21 - - TCP toclient: 21 port groups, 21 unique SGH's, 0 copies 19/1/2022 -- 15:18:21 - - UDP toserver: 41 port groups, 38 unique SGH's, 3 copies 19/1/2022 -- 15:18:21 - - UDP toclient: 21 port groups, 17 unique SGH's, 4 copies 19/1/2022 -- 15:18:21 - - OTHER toserver: 254 proto groups, 3 unique SGH's, 251 copies 19/1/2022 -- 15:18:21 - - OTHER toclient: 254 proto groups, 0 unique SGH's, 254 copies 19/1/2022 -- 15:18:30 - - Unique rule groups: 118 19/1/2022 -- 15:18:30 - - Builtin MPM "toserver TCP packet": 26 19/1/2022 -- 15:18:30 - - Builtin MPM "toclient TCP packet": 20 19/1/2022 -- 15:18:30 - - Builtin MPM "toserver TCP stream": 30 19/1/2022 -- 15:18:30 - - Builtin MPM "toclient TCP stream": 21 19/1/2022 -- 15:18:30 - - Builtin MPM "toserver UDP packet": 38 19/1/2022 -- 15:18:30 - - Builtin MPM "toclient UDP packet": 16 19/1/2022 -- 15:18:30 - - Builtin MPM "other IP packet": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_uri (http)": 8 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_uri (http2)": 8 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_raw_uri (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_raw_uri (http2)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_request_line (http)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_client_body (http)": 5 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_response_line (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_header (http)": 8 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_header (http)": 8 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_header_names (http)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_header_names (http)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_accept (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_accept (http2)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_accept_enc (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_accept_enc (http2)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_accept_lang (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_accept_lang (http2)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_referer (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_referer (http2)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_content_len (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_content_len (http2)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_content_len (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_content_len (http2)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_content_type (http)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_content_type (http2)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_content_type (http)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_content_type (http2)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_protocol (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_protocol (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_start (http)": 4 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_start (http)": 4 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_raw_header (http)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_raw_header (http)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_method (http)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_method (http2)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_cookie (http)": 3 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_cookie (http)": 3 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_cookie (http2)": 3 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_cookie (http2)": 3 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_user_agent (http)": 6 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_user_agent (http2)": 6 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_host (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_raw_host (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver http_raw_host (http2)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_stat_code (http)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient http_stat_code (http2)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver dns_query (dns)": 4 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver tls.sni (tls)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient tls.cert_issuer (tls)": 5 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient tls.cert_subject (tls)": 2 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient tls.cert_serial (tls)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver ssh.proto (ssh)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient ssh.proto (ssh)": 1 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver file_data (smtp)": 7 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient file_data (http)": 7 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver file_data (smb)": 7 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient file_data (smb)": 7 19/1/2022 -- 15:18:30 - - AppLayer MPM "toserver file_data (http2)": 7 19/1/2022 -- 15:18:30 - - AppLayer MPM "toclient file_data (http2)": 7 19/1/2022 -- 15:18:31 - - AutoFP mode using "Hash" flow load balancer 19/1/2022 -- 15:18:31 - - using 1 flow manager threads 19/1/2022 -- 15:18:31 - - using 1 flow recycler threads 19/1/2022 -- 15:18:31 - - all 10 packet processing threads, 4 management threads initialized, engine started. 19/1/2022 -- 15:19:02 - - [ERRCODE: SC_ERR_WINDIVERT_GENERIC(312)] - WinDivertOpen failed, error 87 (0x00000057): Paramètre incorrect. The WinDivert packet filter string is invalid. 19/1/2022 -- 15:19:02 - - [ERRCODE: SC_ERR_FATAL(171)] - thread TX#00 failed 19/1/2022 -- 15:20:57 - - This is Suricata version 6.0.3 RELEASE running in SYSTEM mode 19/1/2022 -- 15:20:57 - - CPUs/cores online: 8 19/1/2022 -- 15:20:57 - - 'default' server has 'request-body-minimal-inspect-size' set to 33940 and 'request-body-inspect-window' set to 4255 after randomization. 19/1/2022 -- 15:20:57 - - 'default' server has 'response-body-minimal-inspect-size' set to 39447 and 'response-body-inspect-window' set to 16080 after randomization. 19/1/2022 -- 15:20:57 - - SMB stream depth: 0 19/1/2022 -- 15:20:57 - - Protocol detection and parser disabled for modbus protocol. 19/1/2022 -- 15:20:57 - - Protocol detection and parser disabled for enip protocol. 19/1/2022 -- 15:20:57 - - Protocol detection and parser disabled for DNP3. 19/1/2022 -- 15:20:57 - - Found a global MTU of 1500 19/1/2022 -- 15:20:57 - - allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64 19/1/2022 -- 15:20:57 - - preallocated 1000 hosts of size 104 19/1/2022 -- 15:20:57 - - host memory usage: 366144 bytes, maximum: 33554432 19/1/2022 -- 15:20:57 - - Configuring core dump is not yet supported on Windows. 19/1/2022 -- 15:20:57 - - allocated 1572864 bytes of memory for the defrag hash... 65536 buckets of size 24 19/1/2022 -- 15:20:57 - - preallocated 65535 defrag trackers of size 120 19/1/2022 -- 15:20:57 - - defrag memory usage: 9437064 bytes, maximum: 33554432 19/1/2022 -- 15:20:57 - - flow size 264, memcap allows for 508400 flows. Per hash row in perfect conditions 7 19/1/2022 -- 15:20:57 - - stream "prealloc-sessions": 2048 (per thread) 19/1/2022 -- 15:20:57 - - stream "memcap": 67108864 19/1/2022 -- 15:20:57 - - stream "midstream" session pickups: disabled 19/1/2022 -- 15:20:57 - - stream "async-oneside": disabled 19/1/2022 -- 15:20:57 - - stream "checksum-validation": disabled 19/1/2022 -- 15:20:57 - - stream."inline": disabled 19/1/2022 -- 15:20:57 - - stream "bypass": disabled 19/1/2022 -- 15:20:57 - - stream "max-synack-queued": 5 19/1/2022 -- 15:20:57 - - stream.reassembly "memcap": 268435456 19/1/2022 -- 15:20:57 - - stream.reassembly "depth": 1048576 19/1/2022 -- 15:20:57 - - stream.reassembly "toserver-chunk-size": 2571 19/1/2022 -- 15:20:57 - - stream.reassembly "toclient-chunk-size": 2582 19/1/2022 -- 15:20:57 - - stream.reassembly.raw: enabled 19/1/2022 -- 15:20:57 - - stream.reassembly "segment-prealloc": 2048 19/1/2022 -- 15:20:57 - - fast output device (regular) initialized: fast.log 19/1/2022 -- 15:20:57 - - eve-log output device (regular) initialized: eve.json 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'alert' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'anomaly' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'http' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'dns' 19/1/2022 -- 15:20:57 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:20:57 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'tls' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'files' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'smtp' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'ftp' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'rdp' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'nfs' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'smb' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'tftp' 19/1/2022 -- 15:20:57 - - enabling 'eve-log' module 'ikev2' 19/1/2022 -- 15:20:58 - - enabling 'eve-log' module 'dcerpc' 19/1/2022 -- 15:20:58 - - enabling 'eve-log' module 'krb5' 19/1/2022 -- 15:20:58 - - enabling 'eve-log' module 'snmp' 19/1/2022 -- 15:20:58 - - enabling 'eve-log' module 'rfb' 19/1/2022 -- 15:20:58 - - enabling 'eve-log' module 'sip' 19/1/2022 -- 15:20:58 - - enabling 'eve-log' module 'dhcp' 19/1/2022 -- 15:20:58 - - enabling 'eve-log' module 'ssh' 19/1/2022 -- 15:20:58 - - enabling 'eve-log' module 'mqtt' 19/1/2022 -- 15:20:58 - - enabling 'eve-log' module 'stats' 19/1/2022 -- 15:20:58 - - enabling 'eve-log' module 'flow' 19/1/2022 -- 15:20:58 - - stats output device (regular) initialized: stats.log 19/1/2022 -- 15:20:58 - - Delayed detect disabled 19/1/2022 -- 15:20:58 - - pattern matchers: MPM: ac, SPM: bm 19/1/2022 -- 15:20:58 - - grouping: tcp-whitelist (default) 53, 80, 139, 443, 445, 1433, 3306, 3389, 6666, 6667, 8080 19/1/2022 -- 15:20:58 - - grouping: udp-whitelist (default) 53, 135, 5060 19/1/2022 -- 15:20:58 - - prefilter engines: MPM 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_request_line 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_client_body 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_response_line 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_host 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_stat_msg 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for dns_query 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for tls.sni 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for tls.cert_issuer 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for tls.cert_subject 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for tls.cert_serial 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for tls.cert_fingerprint 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for tls.certs 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ja3.hash 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ja3.string 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ja3s.hash 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ja3s.string 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for smb_named_pipe 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for smb_share 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ssh.hassh 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ssh.hassh.server 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ssh.hassh.string 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for ssh.hassh.server.string 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for krb5_cname 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for krb5_sname 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for sip.uri 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for sip.stat_msg 19/1/2022 -- 15:20:58 - - using shared mpm ctx' for sip.request_line 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for sip.response_line 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for rfb.name 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for mqtt.connect.clientid 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for mqtt.connect.username 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for mqtt.connect.password 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for mqtt.connect.willtopic 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for mqtt.connect.willmessage 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for mqtt.publish.topic 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for mqtt.publish.message 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for mqtt.subscribe.topic 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for mqtt.unsubscribe.topic 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for icmpv4.hdr 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for tcp.hdr 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for udp.hdr 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for icmpv6.hdr 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for ipv4.hdr 19/1/2022 -- 15:20:59 - - using shared mpm ctx' for ipv6.hdr 19/1/2022 -- 15:20:59 - - IP reputation disabled 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\botcc.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\botcc.portgrouped.rules 19/1/2022 -- 15:20:59 - - No rules loaded from botcc.portgrouped.rules. 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\ciarmy.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\compromised.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\drop.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\dshield.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-activex.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-attack_response.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-chat.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-current_events.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-dns.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-dos.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-exploit.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-ftp.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-games.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-icmp_info.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-icmp.rules 19/1/2022 -- 15:20:59 - - No rules loaded from emerging-icmp.rules. 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-imap.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-inappropriate.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-info.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-malware.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-misc.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-mobile_malware.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-netbios.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-p2p.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-policy.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-pop3.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-rpc.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-scada.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-scan.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-shellcode.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-smtp.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-snmp.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-sql.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-telnet.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-tftp.rules 19/1/2022 -- 15:20:59 - - Loading rule file: C:\Suricata\rules\emerging-trojan.rules 19/1/2022 -- 15:21:00 - - Loading rule file: C:\Suricata\rules\emerging-user_agents.rules 19/1/2022 -- 15:21:00 - - Loading rule file: C:\Suricata\rules\emerging-voip.rules 19/1/2022 -- 15:21:00 - - Loading rule file: C:\Suricata\rules\emerging-web_client.rules 19/1/2022 -- 15:21:00 - - Loading rule file: C:\Suricata\rules\emerging-web_server.rules 19/1/2022 -- 15:21:00 - - Loading rule file: C:\Suricata\rules\emerging-web_specific_apps.rules 19/1/2022 -- 15:21:00 - - Loading rule file: C:\Suricata\rules\emerging-worm.rules 19/1/2022 -- 15:21:00 - - Loading rule file: C:\Suricata\rules\tor.rules 19/1/2022 -- 15:21:00 - - 44 rule files processed. 23850 rules successfully loaded, 0 rules failed 19/1/2022 -- 15:21:00 - - Threshold config parsed: 0 rule(s) found 19/1/2022 -- 15:21:00 - - using shared mpm ctx' for tcp-packet 19/1/2022 -- 15:21:00 - - using shared mpm ctx' for tcp-stream 19/1/2022 -- 15:21:00 - - using shared mpm ctx' for udp-packet 19/1/2022 -- 15:21:00 - - using shared mpm ctx' for other-ip 19/1/2022 -- 15:21:00 - - 23853 signatures processed. 1289 are IP-only rules, 4139 are inspecting packet payload, 18400 inspect application layer, 0 are decoder event only 19/1/2022 -- 15:21:00 - - building signature grouping structure, stage 1: preprocessing rules... complete 19/1/2022 -- 15:21:00 - - TCP toserver: 41 port groups, 39 unique SGH's, 2 copies 19/1/2022 -- 15:21:01 - - TCP toclient: 21 port groups, 21 unique SGH's, 0 copies 19/1/2022 -- 15:21:01 - - UDP toserver: 41 port groups, 38 unique SGH's, 3 copies 19/1/2022 -- 15:21:01 - - UDP toclient: 21 port groups, 17 unique SGH's, 4 copies 19/1/2022 -- 15:21:01 - - OTHER toserver: 254 proto groups, 3 unique SGH's, 251 copies 19/1/2022 -- 15:21:01 - - OTHER toclient: 254 proto groups, 0 unique SGH's, 254 copies 19/1/2022 -- 15:21:09 - - Unique rule groups: 118 19/1/2022 -- 15:21:09 - - Builtin MPM "toserver TCP packet": 26 19/1/2022 -- 15:21:09 - - Builtin MPM "toclient TCP packet": 20 19/1/2022 -- 15:21:09 - - Builtin MPM "toserver TCP stream": 30 19/1/2022 -- 15:21:09 - - Builtin MPM "toclient TCP stream": 21 19/1/2022 -- 15:21:09 - - Builtin MPM "toserver UDP packet": 38 19/1/2022 -- 15:21:09 - - Builtin MPM "toclient UDP packet": 16 19/1/2022 -- 15:21:09 - - Builtin MPM "other IP packet": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_uri (http)": 8 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_uri (http2)": 8 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_raw_uri (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_raw_uri (http2)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_request_line (http)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_client_body (http)": 5 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_response_line (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_header (http)": 8 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_header (http)": 8 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_header_names (http)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_header_names (http)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_accept (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_accept (http2)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_accept_enc (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_accept_enc (http2)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_accept_lang (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_accept_lang (http2)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_referer (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_referer (http2)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_content_len (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_content_len (http2)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_content_len (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_content_len (http2)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_content_type (http)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_content_type (http2)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_content_type (http)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_content_type (http2)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_protocol (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_protocol (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_start (http)": 4 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_start (http)": 4 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_raw_header (http)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_raw_header (http)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_method (http)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_method (http2)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_cookie (http)": 3 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_cookie (http)": 3 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_cookie (http2)": 3 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_cookie (http2)": 3 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_user_agent (http)": 6 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_user_agent (http2)": 6 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_host (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_raw_host (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver http_raw_host (http2)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_stat_code (http)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient http_stat_code (http2)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver dns_query (dns)": 4 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver tls.sni (tls)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient tls.cert_issuer (tls)": 5 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient tls.cert_subject (tls)": 2 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient tls.cert_serial (tls)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver ssh.proto (ssh)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient ssh.proto (ssh)": 1 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver file_data (smtp)": 7 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient file_data (http)": 7 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver file_data (smb)": 7 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient file_data (smb)": 7 19/1/2022 -- 15:21:09 - - AppLayer MPM "toserver file_data (http2)": 7 19/1/2022 -- 15:21:09 - - AppLayer MPM "toclient file_data (http2)": 7 19/1/2022 -- 15:21:10 - - AutoFP mode using "Hash" flow load balancer 19/1/2022 -- 15:21:10 - - using 1 flow manager threads 19/1/2022 -- 15:21:10 - - using 1 flow recycler threads 19/1/2022 -- 15:21:10 - - all 10 packet processing threads, 4 management threads initialized, engine started. 19/1/2022 -- 15:21:29 - - [ERRCODE: SC_ERR_WINDIVERT_GENERIC(312)] - WinDivertOpen failed, error 87 (0x00000057): Paramètre incorrect. The WinDivert packet filter string is invalid. 19/1/2022 -- 15:21:30 - - [ERRCODE: SC_ERR_FATAL(171)] - thread TX#00 failed 19/1/2022 -- 15:41:53 - - This is Suricata version 6.0.3 RELEASE running in SYSTEM mode 19/1/2022 -- 15:41:53 - - CPUs/cores online: 8 19/1/2022 -- 15:41:53 - - 'default' server has 'request-body-minimal-inspect-size' set to 33795 and 'request-body-inspect-window' set to 4030 after randomization. 19/1/2022 -- 15:41:53 - - 'default' server has 'response-body-minimal-inspect-size' set to 40315 and 'response-body-inspect-window' set to 16119 after randomization. 19/1/2022 -- 15:41:53 - - SMB stream depth: 0 19/1/2022 -- 15:41:53 - - Protocol detection and parser disabled for modbus protocol. 19/1/2022 -- 15:41:53 - - Protocol detection and parser disabled for enip protocol. 19/1/2022 -- 15:41:53 - - Protocol detection and parser disabled for DNP3. 19/1/2022 -- 15:41:53 - - Found a global MTU of 1500 19/1/2022 -- 15:41:54 - - allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64 19/1/2022 -- 15:41:54 - - preallocated 1000 hosts of size 104 19/1/2022 -- 15:41:54 - - host memory usage: 366144 bytes, maximum: 33554432 19/1/2022 -- 15:41:54 - - Configuring core dump is not yet supported on Windows. 19/1/2022 -- 15:41:54 - - allocated 1572864 bytes of memory for the defrag hash... 65536 buckets of size 24 19/1/2022 -- 15:41:54 - - preallocated 65535 defrag trackers of size 120 19/1/2022 -- 15:41:54 - - defrag memory usage: 9437064 bytes, maximum: 33554432 19/1/2022 -- 15:41:54 - - flow size 264, memcap allows for 508400 flows. Per hash row in perfect conditions 7 19/1/2022 -- 15:41:54 - - stream "prealloc-sessions": 2048 (per thread) 19/1/2022 -- 15:41:54 - - stream "memcap": 67108864 19/1/2022 -- 15:41:54 - - stream "midstream" session pickups: disabled 19/1/2022 -- 15:41:54 - - stream "async-oneside": disabled 19/1/2022 -- 15:41:54 - - stream "checksum-validation": disabled 19/1/2022 -- 15:41:54 - - stream."inline": disabled 19/1/2022 -- 15:41:54 - - stream "bypass": disabled 19/1/2022 -- 15:41:54 - - stream "max-synack-queued": 5 19/1/2022 -- 15:41:54 - - stream.reassembly "memcap": 268435456 19/1/2022 -- 15:41:54 - - stream.reassembly "depth": 1048576 19/1/2022 -- 15:41:54 - - stream.reassembly "toserver-chunk-size": 2572 19/1/2022 -- 15:41:54 - - stream.reassembly "toclient-chunk-size": 2457 19/1/2022 -- 15:41:54 - - stream.reassembly.raw: enabled 19/1/2022 -- 15:41:54 - - stream.reassembly "segment-prealloc": 2048 19/1/2022 -- 15:41:54 - - fast output device (regular) initialized: fast.log 19/1/2022 -- 15:41:54 - - eve-log output device (regular) initialized: eve.json 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'alert' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'anomaly' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'http' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'dns' 19/1/2022 -- 15:41:54 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:41:54 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'tls' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'files' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'smtp' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'ftp' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'rdp' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'nfs' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'smb' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'tftp' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'ikev2' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'dcerpc' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'krb5' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'snmp' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'rfb' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'sip' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'dhcp' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'ssh' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'mqtt' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'stats' 19/1/2022 -- 15:41:54 - - enabling 'eve-log' module 'flow' 19/1/2022 -- 15:41:54 - - stats output device (regular) initialized: stats.log 19/1/2022 -- 15:41:54 - - Delayed detect disabled 19/1/2022 -- 15:41:54 - - pattern matchers: MPM: ac, SPM: bm 19/1/2022 -- 15:41:54 - - grouping: tcp-whitelist (default) 53, 80, 139, 443, 445, 1433, 3306, 3389, 6666, 6667, 8080 19/1/2022 -- 15:41:54 - - grouping: udp-whitelist (default) 53, 135, 5060 19/1/2022 -- 15:41:54 - - prefilter engines: MPM 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_request_line 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_client_body 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_response_line 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_host 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_stat_msg 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for dns_query 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for tls.sni 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for tls.cert_issuer 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for tls.cert_subject 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for tls.cert_serial 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for tls.cert_fingerprint 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for tls.certs 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ja3.hash 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ja3.string 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ja3s.hash 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ja3s.string 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for smb_named_pipe 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for smb_share 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ssh.hassh 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ssh.hassh.server 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ssh.hassh.string 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for ssh.hassh.server.string 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for krb5_cname 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for krb5_sname 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for sip.uri 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for sip.stat_msg 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for sip.request_line 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for sip.response_line 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for rfb.name 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for mqtt.connect.clientid 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for mqtt.connect.username 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for mqtt.connect.password 19/1/2022 -- 15:41:54 - - using shared mpm ctx' for mqtt.connect.willtopic 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for mqtt.connect.willmessage 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for mqtt.publish.topic 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for mqtt.publish.message 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for mqtt.subscribe.topic 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for mqtt.unsubscribe.topic 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for icmpv4.hdr 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for tcp.hdr 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for udp.hdr 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for icmpv6.hdr 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for ipv4.hdr 19/1/2022 -- 15:41:55 - - using shared mpm ctx' for ipv6.hdr 19/1/2022 -- 15:41:55 - - IP reputation disabled 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\botcc.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\botcc.portgrouped.rules 19/1/2022 -- 15:41:55 - - No rules loaded from botcc.portgrouped.rules. 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\ciarmy.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\compromised.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\drop.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\dshield.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-activex.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-attack_response.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-chat.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-current_events.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-dns.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-dos.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-exploit.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-ftp.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-games.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-icmp_info.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-icmp.rules 19/1/2022 -- 15:41:55 - - No rules loaded from emerging-icmp.rules. 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-imap.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-inappropriate.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-info.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-malware.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-misc.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-mobile_malware.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-netbios.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-p2p.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-policy.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-pop3.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-rpc.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-scada.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-scan.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-shellcode.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-smtp.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-snmp.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-sql.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-telnet.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-tftp.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-trojan.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-user_agents.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-voip.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-web_client.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-web_server.rules 19/1/2022 -- 15:41:55 - - Loading rule file: C:\Suricata\rules\emerging-web_specific_apps.rules 19/1/2022 -- 15:41:56 - - Loading rule file: C:\Suricata\rules\emerging-worm.rules 19/1/2022 -- 15:41:56 - - Loading rule file: C:\Suricata\rules\tor.rules 19/1/2022 -- 15:41:56 - - 44 rule files processed. 23850 rules successfully loaded, 0 rules failed 19/1/2022 -- 15:41:56 - - Threshold config parsed: 0 rule(s) found 19/1/2022 -- 15:41:56 - - using shared mpm ctx' for tcp-packet 19/1/2022 -- 15:41:56 - - using shared mpm ctx' for tcp-stream 19/1/2022 -- 15:41:56 - - using shared mpm ctx' for udp-packet 19/1/2022 -- 15:41:56 - - using shared mpm ctx' for other-ip 19/1/2022 -- 15:41:56 - - 23853 signatures processed. 1289 are IP-only rules, 4139 are inspecting packet payload, 18400 inspect application layer, 0 are decoder event only 19/1/2022 -- 15:41:56 - - building signature grouping structure, stage 1: preprocessing rules... complete 19/1/2022 -- 15:41:56 - - TCP toserver: 41 port groups, 39 unique SGH's, 2 copies 19/1/2022 -- 15:41:56 - - TCP toclient: 21 port groups, 21 unique SGH's, 0 copies 19/1/2022 -- 15:41:56 - - UDP toserver: 41 port groups, 38 unique SGH's, 3 copies 19/1/2022 -- 15:41:56 - - UDP toclient: 21 port groups, 17 unique SGH's, 4 copies 19/1/2022 -- 15:41:56 - - OTHER toserver: 254 proto groups, 3 unique SGH's, 251 copies 19/1/2022 -- 15:41:56 - - OTHER toclient: 254 proto groups, 0 unique SGH's, 254 copies 19/1/2022 -- 15:42:05 - - Unique rule groups: 118 19/1/2022 -- 15:42:05 - - Builtin MPM "toserver TCP packet": 26 19/1/2022 -- 15:42:05 - - Builtin MPM "toclient TCP packet": 20 19/1/2022 -- 15:42:05 - - Builtin MPM "toserver TCP stream": 30 19/1/2022 -- 15:42:05 - - Builtin MPM "toclient TCP stream": 21 19/1/2022 -- 15:42:05 - - Builtin MPM "toserver UDP packet": 38 19/1/2022 -- 15:42:05 - - Builtin MPM "toclient UDP packet": 16 19/1/2022 -- 15:42:05 - - Builtin MPM "other IP packet": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_uri (http)": 8 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_uri (http2)": 8 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_raw_uri (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_raw_uri (http2)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_request_line (http)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_client_body (http)": 5 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_response_line (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_header (http)": 8 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_header (http)": 8 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_header_names (http)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_header_names (http)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_accept (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_accept (http2)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_accept_enc (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_accept_enc (http2)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_accept_lang (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_accept_lang (http2)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_referer (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_referer (http2)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_content_len (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_content_len (http2)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_content_len (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_content_len (http2)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_content_type (http)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_content_type (http2)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_content_type (http)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_content_type (http2)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_protocol (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_protocol (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_start (http)": 4 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_start (http)": 4 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_raw_header (http)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_raw_header (http)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_method (http)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_method (http2)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_cookie (http)": 3 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_cookie (http)": 3 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_cookie (http2)": 3 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_cookie (http2)": 3 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_user_agent (http)": 6 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_user_agent (http2)": 6 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_host (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_raw_host (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver http_raw_host (http2)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_stat_code (http)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient http_stat_code (http2)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver dns_query (dns)": 4 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver tls.sni (tls)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient tls.cert_issuer (tls)": 5 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient tls.cert_subject (tls)": 2 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient tls.cert_serial (tls)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver ssh.proto (ssh)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient ssh.proto (ssh)": 1 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver file_data (smtp)": 7 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient file_data (http)": 7 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver file_data (smb)": 7 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient file_data (smb)": 7 19/1/2022 -- 15:42:05 - - AppLayer MPM "toserver file_data (http2)": 7 19/1/2022 -- 15:42:05 - - AppLayer MPM "toclient file_data (http2)": 7 19/1/2022 -- 15:42:06 - - AutoFP mode using "Hash" flow load balancer 19/1/2022 -- 15:42:06 - - [ERRCODE: SC_ERR_THREAD_QUEUE(235)] - queue "pickup8" doesn't have a writer (id 8, max 9) 19/1/2022 -- 15:42:06 - - [ERRCODE: SC_ERR_FATAL(171)] - fatal error during threading setup 19/1/2022 -- 15:42:46 - - This is Suricata version 6.0.3 RELEASE running in SYSTEM mode 19/1/2022 -- 15:42:46 - - CPUs/cores online: 8 19/1/2022 -- 15:42:46 - - 'default' server has 'request-body-minimal-inspect-size' set to 32599 and 'request-body-inspect-window' set to 4226 after randomization. 19/1/2022 -- 15:42:46 - - 'default' server has 'response-body-minimal-inspect-size' set to 39040 and 'response-body-inspect-window' set to 17117 after randomization. 19/1/2022 -- 15:42:46 - - SMB stream depth: 0 19/1/2022 -- 15:42:46 - - Protocol detection and parser disabled for modbus protocol. 19/1/2022 -- 15:42:46 - - Protocol detection and parser disabled for enip protocol. 19/1/2022 -- 15:42:46 - - Protocol detection and parser disabled for DNP3. 19/1/2022 -- 15:42:46 - - Found a global MTU of 1500 19/1/2022 -- 15:42:46 - - allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64 19/1/2022 -- 15:42:46 - - preallocated 1000 hosts of size 104 19/1/2022 -- 15:42:46 - - host memory usage: 366144 bytes, maximum: 33554432 19/1/2022 -- 15:42:46 - - Configuring core dump is not yet supported on Windows. 19/1/2022 -- 15:42:46 - - allocated 1572864 bytes of memory for the defrag hash... 65536 buckets of size 24 19/1/2022 -- 15:42:46 - - preallocated 65535 defrag trackers of size 120 19/1/2022 -- 15:42:46 - - defrag memory usage: 9437064 bytes, maximum: 33554432 19/1/2022 -- 15:42:46 - - flow size 264, memcap allows for 508400 flows. Per hash row in perfect conditions 7 19/1/2022 -- 15:42:46 - - stream "prealloc-sessions": 2048 (per thread) 19/1/2022 -- 15:42:46 - - stream "memcap": 67108864 19/1/2022 -- 15:42:46 - - stream "midstream" session pickups: disabled 19/1/2022 -- 15:42:46 - - stream "async-oneside": disabled 19/1/2022 -- 15:42:46 - - stream "checksum-validation": disabled 19/1/2022 -- 15:42:46 - - stream."inline": disabled 19/1/2022 -- 15:42:46 - - stream "bypass": disabled 19/1/2022 -- 15:42:46 - - stream "max-synack-queued": 5 19/1/2022 -- 15:42:46 - - stream.reassembly "memcap": 268435456 19/1/2022 -- 15:42:46 - - stream.reassembly "depth": 1048576 19/1/2022 -- 15:42:46 - - stream.reassembly "toserver-chunk-size": 2581 19/1/2022 -- 15:42:46 - - stream.reassembly "toclient-chunk-size": 2560 19/1/2022 -- 15:42:46 - - stream.reassembly.raw: enabled 19/1/2022 -- 15:42:46 - - stream.reassembly "segment-prealloc": 2048 19/1/2022 -- 15:42:46 - - fast output device (regular) initialized: fast.log 19/1/2022 -- 15:42:46 - - eve-log output device (regular) initialized: eve.json 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'alert' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'anomaly' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'http' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'dns' 19/1/2022 -- 15:42:46 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:42:46 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'tls' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'files' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'smtp' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'ftp' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'rdp' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'nfs' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'smb' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'tftp' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'ikev2' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'dcerpc' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'krb5' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'snmp' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'rfb' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'sip' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'dhcp' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'ssh' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'mqtt' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'stats' 19/1/2022 -- 15:42:46 - - enabling 'eve-log' module 'flow' 19/1/2022 -- 15:42:46 - - stats output device (regular) initialized: stats.log 19/1/2022 -- 15:42:46 - - Delayed detect disabled 19/1/2022 -- 15:42:46 - - pattern matchers: MPM: ac, SPM: bm 19/1/2022 -- 15:42:46 - - grouping: tcp-whitelist (default) 53, 80, 139, 443, 445, 1433, 3306, 3389, 6666, 6667, 8080 19/1/2022 -- 15:42:46 - - grouping: udp-whitelist (default) 53, 135, 5060 19/1/2022 -- 15:42:46 - - prefilter engines: MPM 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_request_line 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_client_body 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_response_line 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_host 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_stat_msg 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for dns_query 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for tls.sni 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for tls.cert_issuer 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for tls.cert_subject 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for tls.cert_serial 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for tls.cert_fingerprint 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for tls.certs 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for ja3.hash 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for ja3.string 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for ja3s.hash 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for ja3s.string 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:42:46 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for smb_named_pipe 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for smb_share 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for ssh.hassh 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for ssh.hassh.server 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for ssh.hassh.string 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for ssh.hassh.server.string 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for krb5_cname 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for krb5_sname 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for sip.uri 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for sip.stat_msg 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for sip.request_line 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for sip.response_line 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for rfb.name 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for mqtt.connect.clientid 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for mqtt.connect.username 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for mqtt.connect.password 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for mqtt.connect.willtopic 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for mqtt.connect.willmessage 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for mqtt.publish.topic 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for mqtt.publish.message 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for mqtt.subscribe.topic 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for mqtt.unsubscribe.topic 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for icmpv4.hdr 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for tcp.hdr 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for udp.hdr 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for icmpv6.hdr 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for ipv4.hdr 19/1/2022 -- 15:42:47 - - using shared mpm ctx' for ipv6.hdr 19/1/2022 -- 15:42:47 - - IP reputation disabled 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\botcc.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\botcc.portgrouped.rules 19/1/2022 -- 15:42:47 - - No rules loaded from botcc.portgrouped.rules. 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\ciarmy.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\compromised.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\drop.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\dshield.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-activex.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-attack_response.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-chat.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-current_events.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-dns.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-dos.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-exploit.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-ftp.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-games.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-icmp_info.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-icmp.rules 19/1/2022 -- 15:42:47 - - No rules loaded from emerging-icmp.rules. 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-imap.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-inappropriate.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-info.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-malware.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-misc.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-mobile_malware.rules 19/1/2022 -- 15:42:47 - - Loading rule file: C:\Suricata\rules\emerging-netbios.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-p2p.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-policy.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-pop3.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-rpc.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-scada.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-scan.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-shellcode.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-smtp.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-snmp.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-sql.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-telnet.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-tftp.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-trojan.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-user_agents.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-voip.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-web_client.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-web_server.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-web_specific_apps.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\emerging-worm.rules 19/1/2022 -- 15:42:48 - - Loading rule file: C:\Suricata\rules\tor.rules 19/1/2022 -- 15:42:48 - - 44 rule files processed. 23850 rules successfully loaded, 0 rules failed 19/1/2022 -- 15:42:48 - - Threshold config parsed: 0 rule(s) found 19/1/2022 -- 15:42:49 - - using shared mpm ctx' for tcp-packet 19/1/2022 -- 15:42:49 - - using shared mpm ctx' for tcp-stream 19/1/2022 -- 15:42:49 - - using shared mpm ctx' for udp-packet 19/1/2022 -- 15:42:49 - - using shared mpm ctx' for other-ip 19/1/2022 -- 15:42:49 - - 23853 signatures processed. 1289 are IP-only rules, 4139 are inspecting packet payload, 18400 inspect application layer, 0 are decoder event only 19/1/2022 -- 15:42:49 - - building signature grouping structure, stage 1: preprocessing rules... complete 19/1/2022 -- 15:42:49 - - TCP toserver: 41 port groups, 39 unique SGH's, 2 copies 19/1/2022 -- 15:42:49 - - TCP toclient: 21 port groups, 21 unique SGH's, 0 copies 19/1/2022 -- 15:42:49 - - UDP toserver: 41 port groups, 38 unique SGH's, 3 copies 19/1/2022 -- 15:42:49 - - UDP toclient: 21 port groups, 17 unique SGH's, 4 copies 19/1/2022 -- 15:42:49 - - OTHER toserver: 254 proto groups, 3 unique SGH's, 251 copies 19/1/2022 -- 15:42:49 - - OTHER toclient: 254 proto groups, 0 unique SGH's, 254 copies 19/1/2022 -- 15:42:58 - - Unique rule groups: 118 19/1/2022 -- 15:42:58 - - Builtin MPM "toserver TCP packet": 26 19/1/2022 -- 15:42:58 - - Builtin MPM "toclient TCP packet": 20 19/1/2022 -- 15:42:58 - - Builtin MPM "toserver TCP stream": 30 19/1/2022 -- 15:42:58 - - Builtin MPM "toclient TCP stream": 21 19/1/2022 -- 15:42:58 - - Builtin MPM "toserver UDP packet": 38 19/1/2022 -- 15:42:58 - - Builtin MPM "toclient UDP packet": 16 19/1/2022 -- 15:42:58 - - Builtin MPM "other IP packet": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_uri (http)": 8 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_uri (http2)": 8 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_raw_uri (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_raw_uri (http2)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_request_line (http)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_client_body (http)": 5 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_response_line (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_header (http)": 8 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_header (http)": 8 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_header_names (http)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_header_names (http)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_accept (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_accept (http2)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_accept_enc (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_accept_enc (http2)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_accept_lang (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_accept_lang (http2)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_referer (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_referer (http2)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_content_len (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_content_len (http2)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_content_len (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_content_len (http2)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_content_type (http)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_content_type (http2)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_content_type (http)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_content_type (http2)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_protocol (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_protocol (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_start (http)": 4 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_start (http)": 4 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_raw_header (http)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_raw_header (http)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_method (http)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_method (http2)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_cookie (http)": 3 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_cookie (http)": 3 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_cookie (http2)": 3 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_cookie (http2)": 3 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_user_agent (http)": 6 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_user_agent (http2)": 6 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_host (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_raw_host (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver http_raw_host (http2)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_stat_code (http)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient http_stat_code (http2)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver dns_query (dns)": 4 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver tls.sni (tls)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient tls.cert_issuer (tls)": 5 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient tls.cert_subject (tls)": 2 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient tls.cert_serial (tls)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver ssh.proto (ssh)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient ssh.proto (ssh)": 1 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver file_data (smtp)": 7 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient file_data (http)": 7 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver file_data (smb)": 7 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient file_data (smb)": 7 19/1/2022 -- 15:42:58 - - AppLayer MPM "toserver file_data (http2)": 7 19/1/2022 -- 15:42:58 - - AppLayer MPM "toclient file_data (http2)": 7 19/1/2022 -- 15:42:59 - - AutoFP mode using "Hash" flow load balancer 19/1/2022 -- 15:42:59 - - using 1 flow manager threads 19/1/2022 -- 15:42:59 - - using 1 flow recycler threads 19/1/2022 -- 15:42:59 - - all 10 packet processing threads, 4 management threads initialized, engine started. 19/1/2022 -- 15:43:02 - - [ERRCODE: SC_ERR_WINDIVERT_GENERIC(312)] - WinDivertOpen failed, error 87 (0x00000057): Paramètre incorrect. The WinDivert packet filter string is invalid. 19/1/2022 -- 15:43:02 - - [ERRCODE: SC_ERR_FATAL(171)] - thread TX#00 failed 19/1/2022 -- 15:48:42 - - This is Suricata version 6.0.3 RELEASE running in SYSTEM mode 19/1/2022 -- 15:48:42 - - CPUs/cores online: 8 19/1/2022 -- 15:48:42 - - 'default' server has 'request-body-minimal-inspect-size' set to 31166 and 'request-body-inspect-window' set to 4081 after randomization. 19/1/2022 -- 15:48:42 - - 'default' server has 'response-body-minimal-inspect-size' set to 40833 and 'response-body-inspect-window' set to 17002 after randomization. 19/1/2022 -- 15:48:42 - - SMB stream depth: 0 19/1/2022 -- 15:48:42 - - Protocol detection and parser disabled for modbus protocol. 19/1/2022 -- 15:48:42 - - Protocol detection and parser disabled for enip protocol. 19/1/2022 -- 15:48:42 - - Protocol detection and parser disabled for DNP3. 19/1/2022 -- 15:48:42 - - Found a global MTU of 1500 19/1/2022 -- 15:48:42 - - allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64 19/1/2022 -- 15:48:42 - - preallocated 1000 hosts of size 104 19/1/2022 -- 15:48:42 - - host memory usage: 366144 bytes, maximum: 33554432 19/1/2022 -- 15:48:42 - - Configuring core dump is not yet supported on Windows. 19/1/2022 -- 15:48:42 - - allocated 1572864 bytes of memory for the defrag hash... 65536 buckets of size 24 19/1/2022 -- 15:48:42 - - preallocated 65535 defrag trackers of size 120 19/1/2022 -- 15:48:42 - - defrag memory usage: 9437064 bytes, maximum: 33554432 19/1/2022 -- 15:48:42 - - flow size 264, memcap allows for 508400 flows. Per hash row in perfect conditions 7 19/1/2022 -- 15:48:42 - - stream "prealloc-sessions": 2048 (per thread) 19/1/2022 -- 15:48:42 - - stream "memcap": 67108864 19/1/2022 -- 15:48:42 - - stream "midstream" session pickups: disabled 19/1/2022 -- 15:48:42 - - stream "async-oneside": disabled 19/1/2022 -- 15:48:42 - - stream "checksum-validation": disabled 19/1/2022 -- 15:48:42 - - stream."inline": disabled 19/1/2022 -- 15:48:42 - - stream "bypass": disabled 19/1/2022 -- 15:48:42 - - stream "max-synack-queued": 5 19/1/2022 -- 15:48:42 - - stream.reassembly "memcap": 268435456 19/1/2022 -- 15:48:42 - - stream.reassembly "depth": 1048576 19/1/2022 -- 15:48:42 - - stream.reassembly "toserver-chunk-size": 2624 19/1/2022 -- 15:48:42 - - stream.reassembly "toclient-chunk-size": 2604 19/1/2022 -- 15:48:42 - - stream.reassembly.raw: enabled 19/1/2022 -- 15:48:42 - - stream.reassembly "segment-prealloc": 2048 19/1/2022 -- 15:48:42 - - fast output device (regular) initialized: fast.log 19/1/2022 -- 15:48:42 - - eve-log output device (regular) initialized: eve.json 19/1/2022 -- 15:48:42 - - enabling 'eve-log' module 'alert' 19/1/2022 -- 15:48:42 - - enabling 'eve-log' module 'anomaly' 19/1/2022 -- 15:48:42 - - enabling 'eve-log' module 'http' 19/1/2022 -- 15:48:42 - - enabling 'eve-log' module 'dns' 19/1/2022 -- 15:48:42 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:48:42 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:48:42 - - enabling 'eve-log' module 'tls' 19/1/2022 -- 15:48:42 - - enabling 'eve-log' module 'files' 19/1/2022 -- 15:48:42 - - enabling 'eve-log' module 'smtp' 19/1/2022 -- 15:48:42 - - enabling 'eve-log' module 'ftp' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'rdp' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'nfs' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'smb' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'tftp' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'ikev2' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'dcerpc' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'krb5' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'snmp' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'rfb' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'sip' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'dhcp' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'ssh' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'mqtt' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'stats' 19/1/2022 -- 15:48:43 - - enabling 'eve-log' module 'flow' 19/1/2022 -- 15:48:43 - - stats output device (regular) initialized: stats.log 19/1/2022 -- 15:48:43 - - Delayed detect disabled 19/1/2022 -- 15:48:43 - - pattern matchers: MPM: ac, SPM: bm 19/1/2022 -- 15:48:43 - - grouping: tcp-whitelist (default) 53, 80, 139, 443, 445, 1433, 3306, 3389, 6666, 6667, 8080 19/1/2022 -- 15:48:43 - - grouping: udp-whitelist (default) 53, 135, 5060 19/1/2022 -- 15:48:43 - - prefilter engines: MPM 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_request_line 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_client_body 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_response_line 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:43 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http_host 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http_stat_msg 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for dns_query 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for tls.sni 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for tls.cert_issuer 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for tls.cert_subject 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for tls.cert_serial 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for tls.cert_fingerprint 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for tls.certs 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ja3.hash 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ja3.string 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ja3s.hash 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ja3s.string 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for smb_named_pipe 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for smb_share 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ssh.hassh 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ssh.hassh.server 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ssh.hassh.string 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ssh.hassh.server.string 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for krb5_cname 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for krb5_sname 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for sip.uri 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for sip.stat_msg 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for sip.request_line 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for sip.response_line 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for rfb.name 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for mqtt.connect.clientid 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for mqtt.connect.username 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for mqtt.connect.password 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for mqtt.connect.willtopic 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for mqtt.connect.willmessage 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for mqtt.publish.topic 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for mqtt.publish.message 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for mqtt.subscribe.topic 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for mqtt.unsubscribe.topic 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for icmpv4.hdr 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for tcp.hdr 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for udp.hdr 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for icmpv6.hdr 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ipv4.hdr 19/1/2022 -- 15:48:44 - - using shared mpm ctx' for ipv6.hdr 19/1/2022 -- 15:48:44 - - IP reputation disabled 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\botcc.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\botcc.portgrouped.rules 19/1/2022 -- 15:48:44 - - No rules loaded from botcc.portgrouped.rules. 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\ciarmy.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\compromised.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\drop.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\dshield.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-activex.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-attack_response.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-chat.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-current_events.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-dns.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-dos.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-exploit.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-ftp.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-games.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-icmp_info.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-icmp.rules 19/1/2022 -- 15:48:44 - - No rules loaded from emerging-icmp.rules. 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-imap.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-inappropriate.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-info.rules 19/1/2022 -- 15:48:44 - - Loading rule file: C:\Suricata\rules\emerging-malware.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-misc.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-mobile_malware.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-netbios.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-p2p.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-policy.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-pop3.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-rpc.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-scada.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-scan.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-shellcode.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-smtp.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-snmp.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-sql.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-telnet.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-tftp.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-trojan.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-user_agents.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-voip.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-web_client.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-web_server.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-web_specific_apps.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\emerging-worm.rules 19/1/2022 -- 15:48:45 - - Loading rule file: C:\Suricata\rules\tor.rules 19/1/2022 -- 15:48:45 - - 44 rule files processed. 23850 rules successfully loaded, 0 rules failed 19/1/2022 -- 15:48:45 - - Threshold config parsed: 0 rule(s) found 19/1/2022 -- 15:48:46 - - using shared mpm ctx' for tcp-packet 19/1/2022 -- 15:48:46 - - using shared mpm ctx' for tcp-stream 19/1/2022 -- 15:48:46 - - using shared mpm ctx' for udp-packet 19/1/2022 -- 15:48:46 - - using shared mpm ctx' for other-ip 19/1/2022 -- 15:48:46 - - 23853 signatures processed. 1289 are IP-only rules, 4139 are inspecting packet payload, 18400 inspect application layer, 0 are decoder event only 19/1/2022 -- 15:48:46 - - building signature grouping structure, stage 1: preprocessing rules... complete 19/1/2022 -- 15:48:46 - - TCP toserver: 41 port groups, 39 unique SGH's, 2 copies 19/1/2022 -- 15:48:46 - - TCP toclient: 21 port groups, 21 unique SGH's, 0 copies 19/1/2022 -- 15:48:46 - - UDP toserver: 41 port groups, 38 unique SGH's, 3 copies 19/1/2022 -- 15:48:46 - - UDP toclient: 21 port groups, 17 unique SGH's, 4 copies 19/1/2022 -- 15:48:46 - - OTHER toserver: 254 proto groups, 3 unique SGH's, 251 copies 19/1/2022 -- 15:48:46 - - OTHER toclient: 254 proto groups, 0 unique SGH's, 254 copies 19/1/2022 -- 15:48:54 - - Unique rule groups: 118 19/1/2022 -- 15:48:54 - - Builtin MPM "toserver TCP packet": 26 19/1/2022 -- 15:48:54 - - Builtin MPM "toclient TCP packet": 20 19/1/2022 -- 15:48:54 - - Builtin MPM "toserver TCP stream": 30 19/1/2022 -- 15:48:54 - - Builtin MPM "toclient TCP stream": 21 19/1/2022 -- 15:48:54 - - Builtin MPM "toserver UDP packet": 38 19/1/2022 -- 15:48:54 - - Builtin MPM "toclient UDP packet": 16 19/1/2022 -- 15:48:54 - - Builtin MPM "other IP packet": 2 19/1/2022 -- 15:48:54 - - AppLayer MPM "toserver http_uri (http)": 8 19/1/2022 -- 15:48:54 - - AppLayer MPM "toserver http_uri (http2)": 8 19/1/2022 -- 15:48:54 - - AppLayer MPM "toserver http_raw_uri (http)": 1 19/1/2022 -- 15:48:54 - - AppLayer MPM "toserver http_raw_uri (http2)": 1 19/1/2022 -- 15:48:54 - - AppLayer MPM "toserver http_request_line (http)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_client_body (http)": 5 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_response_line (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_header (http)": 8 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_header (http)": 8 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_header_names (http)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_header_names (http)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_accept (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_accept (http2)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_accept_enc (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_accept_enc (http2)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_accept_lang (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_accept_lang (http2)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_referer (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_referer (http2)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_content_len (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_content_len (http2)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_content_len (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_content_len (http2)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_content_type (http)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_content_type (http2)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_content_type (http)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_content_type (http2)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_protocol (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_protocol (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_start (http)": 4 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_start (http)": 4 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_raw_header (http)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_raw_header (http)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_method (http)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_method (http2)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_cookie (http)": 3 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_cookie (http)": 3 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_cookie (http2)": 3 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_cookie (http2)": 3 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_user_agent (http)": 6 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_user_agent (http2)": 6 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_host (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_raw_host (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver http_raw_host (http2)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_stat_code (http)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient http_stat_code (http2)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver dns_query (dns)": 4 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver tls.sni (tls)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient tls.cert_issuer (tls)": 5 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient tls.cert_subject (tls)": 2 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient tls.cert_serial (tls)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver ssh.proto (ssh)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient ssh.proto (ssh)": 1 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver file_data (smtp)": 7 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient file_data (http)": 7 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver file_data (smb)": 7 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient file_data (smb)": 7 19/1/2022 -- 15:48:55 - - AppLayer MPM "toserver file_data (http2)": 7 19/1/2022 -- 15:48:55 - - AppLayer MPM "toclient file_data (http2)": 7 19/1/2022 -- 15:48:56 - - AutoFP mode using "Hash" flow load balancer 19/1/2022 -- 15:48:56 - - using 1 flow manager threads 19/1/2022 -- 15:48:56 - - using 1 flow recycler threads 19/1/2022 -- 15:48:56 - - all 10 packet processing threads, 4 management threads initialized, engine started. 19/1/2022 -- 15:51:40 - - Signal Received. Stopping engine. 19/1/2022 -- 15:51:40 - - 0 new flows, 0 established flows were timed out, 0 flows in closed state 19/1/2022 -- 15:51:45 - - time elapsed 169.571s 19/1/2022 -- 15:51:45 - - 166 flows processed 19/1/2022 -- 15:51:45 - - (RX-1) Packets 775, Bytes 233362, Errors 0 19/1/2022 -- 15:51:45 - - (RX-1) Verdict: Accepted 775, Dropped 0, Replaced 0 19/1/2022 -- 15:51:45 - - AutoFP - Total flow handler queues - 8 19/1/2022 -- 15:51:46 - - Alerts: 0 19/1/2022 -- 15:51:46 - - ippair memory usage: 382144 bytes, maximum: 16777216 19/1/2022 -- 15:51:46 - - host memory usage: 366144 bytes, maximum: 33554432 19/1/2022 -- 15:51:46 - - cleaning up signature grouping structure... complete 19/1/2022 -- 15:52:05 - - This is Suricata version 6.0.3 RELEASE running in SYSTEM mode 19/1/2022 -- 15:52:05 - - CPUs/cores online: 8 19/1/2022 -- 15:52:05 - - 'default' server has 'request-body-minimal-inspect-size' set to 31382 and 'request-body-inspect-window' set to 4108 after randomization. 19/1/2022 -- 15:52:05 - - 'default' server has 'response-body-minimal-inspect-size' set to 42810 and 'response-body-inspect-window' set to 15932 after randomization. 19/1/2022 -- 15:52:05 - - SMB stream depth: 0 19/1/2022 -- 15:52:05 - - Protocol detection and parser disabled for modbus protocol. 19/1/2022 -- 15:52:05 - - Protocol detection and parser disabled for enip protocol. 19/1/2022 -- 15:52:05 - - Protocol detection and parser disabled for DNP3. 19/1/2022 -- 15:52:05 - - Found a global MTU of 1500 19/1/2022 -- 15:52:05 - - allocated 262144 bytes of memory for the host hash... 4096 buckets of size 64 19/1/2022 -- 15:52:05 - - preallocated 1000 hosts of size 104 19/1/2022 -- 15:52:05 - - host memory usage: 366144 bytes, maximum: 33554432 19/1/2022 -- 15:52:05 - - Configuring core dump is not yet supported on Windows. 19/1/2022 -- 15:52:05 - - allocated 1572864 bytes of memory for the defrag hash... 65536 buckets of size 24 19/1/2022 -- 15:52:05 - - preallocated 65535 defrag trackers of size 120 19/1/2022 -- 15:52:05 - - defrag memory usage: 9437064 bytes, maximum: 33554432 19/1/2022 -- 15:52:05 - - flow size 264, memcap allows for 508400 flows. Per hash row in perfect conditions 7 19/1/2022 -- 15:52:05 - - stream "prealloc-sessions": 2048 (per thread) 19/1/2022 -- 15:52:05 - - stream "memcap": 67108864 19/1/2022 -- 15:52:05 - - stream "midstream" session pickups: disabled 19/1/2022 -- 15:52:05 - - stream "async-oneside": disabled 19/1/2022 -- 15:52:05 - - stream "checksum-validation": disabled 19/1/2022 -- 15:52:05 - - stream."inline": disabled 19/1/2022 -- 15:52:05 - - stream "bypass": disabled 19/1/2022 -- 15:52:05 - - stream "max-synack-queued": 5 19/1/2022 -- 15:52:05 - - stream.reassembly "memcap": 268435456 19/1/2022 -- 15:52:05 - - stream.reassembly "depth": 1048576 19/1/2022 -- 15:52:05 - - stream.reassembly "toserver-chunk-size": 2552 19/1/2022 -- 15:52:05 - - stream.reassembly "toclient-chunk-size": 2534 19/1/2022 -- 15:52:05 - - stream.reassembly.raw: enabled 19/1/2022 -- 15:52:05 - - stream.reassembly "segment-prealloc": 2048 19/1/2022 -- 15:52:05 - - fast output device (regular) initialized: fast.log 19/1/2022 -- 15:52:05 - - eve-log output device (regular) initialized: eve.json 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'alert' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'anomaly' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'http' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'dns' 19/1/2022 -- 15:52:05 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:52:05 - - eve-log dns version not set, defaulting to version 2 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'tls' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'files' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'smtp' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'ftp' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'rdp' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'nfs' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'smb' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'tftp' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'ikev2' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'dcerpc' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'krb5' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'snmp' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'rfb' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'sip' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'dhcp' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'ssh' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'mqtt' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'stats' 19/1/2022 -- 15:52:05 - - enabling 'eve-log' module 'flow' 19/1/2022 -- 15:52:05 - - stats output device (regular) initialized: stats.log 19/1/2022 -- 15:52:05 - - Delayed detect disabled 19/1/2022 -- 15:52:05 - - pattern matchers: MPM: ac, SPM: bm 19/1/2022 -- 15:52:05 - - grouping: tcp-whitelist (default) 53, 80, 139, 443, 445, 1433, 3306, 3389, 6666, 6667, 8080 19/1/2022 -- 15:52:05 - - grouping: udp-whitelist (default) 53, 135, 5060 19/1/2022 -- 15:52:05 - - prefilter engines: MPM 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_uri 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_raw_uri 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_request_line 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_client_body 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_response_line 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_header 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_header_names 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_accept 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_accept_enc 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_accept_lang 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_referer 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_connection 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_content_len 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_content_type 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http.server 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http.location 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_protocol 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_start 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_raw_header 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_method 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_cookie 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for file.name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_user_agent 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_host 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_raw_host 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_stat_msg 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http_stat_code 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http2_header_name 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for http2_header 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for dns_query 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for dnp3_data 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for tls.sni 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for tls.cert_issuer 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for tls.cert_subject 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for tls.cert_serial 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for tls.cert_fingerprint 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for tls.certs 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for ja3.hash 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for ja3.string 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for ja3s.hash 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for ja3s.string 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for dce_stub_data 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for smb_named_pipe 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for smb_share 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:52:05 - - using shared mpm ctx' for ssh.proto 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for ssh_software 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for ssh.hassh 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for ssh.hassh.server 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for ssh.hassh.string 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for ssh.hassh.server.string 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for file_data 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for krb5_cname 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for krb5_sname 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for sip.uri 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for sip.protocol 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for sip.method 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for sip.stat_msg 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for sip.request_line 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for sip.response_line 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for rfb.name 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for snmp.community 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for mqtt.connect.clientid 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for mqtt.connect.username 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for mqtt.connect.password 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for mqtt.connect.willtopic 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for mqtt.connect.willmessage 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for mqtt.publish.topic 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for mqtt.publish.message 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for mqtt.subscribe.topic 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for mqtt.unsubscribe.topic 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for icmpv4.hdr 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for tcp.hdr 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for udp.hdr 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for icmpv6.hdr 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for ipv4.hdr 19/1/2022 -- 15:52:06 - - using shared mpm ctx' for ipv6.hdr 19/1/2022 -- 15:52:06 - - IP reputation disabled 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\botcc.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\botcc.portgrouped.rules 19/1/2022 -- 15:52:06 - - No rules loaded from botcc.portgrouped.rules. 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\ciarmy.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\compromised.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\drop.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\dshield.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-activex.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-attack_response.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-chat.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-current_events.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-dns.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-dos.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-exploit.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-ftp.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-games.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-icmp_info.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-icmp.rules 19/1/2022 -- 15:52:06 - - No rules loaded from emerging-icmp.rules. 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-imap.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-inappropriate.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-info.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-malware.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-misc.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-mobile_malware.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-netbios.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-p2p.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-policy.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-pop3.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-rpc.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-scada.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-scan.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-shellcode.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-smtp.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-snmp.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-sql.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-telnet.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-tftp.rules 19/1/2022 -- 15:52:06 - - Loading rule file: C:\Suricata\rules\emerging-trojan.rules 19/1/2022 -- 15:52:07 - - Loading rule file: C:\Suricata\rules\emerging-user_agents.rules 19/1/2022 -- 15:52:07 - - Loading rule file: C:\Suricata\rules\emerging-voip.rules 19/1/2022 -- 15:52:07 - - Loading rule file: C:\Suricata\rules\emerging-web_client.rules 19/1/2022 -- 15:52:07 - - Loading rule file: C:\Suricata\rules\emerging-web_server.rules 19/1/2022 -- 15:52:07 - - Loading rule file: C:\Suricata\rules\emerging-web_specific_apps.rules 19/1/2022 -- 15:52:07 - - Loading rule file: C:\Suricata\rules\emerging-worm.rules 19/1/2022 -- 15:52:07 - - Loading rule file: C:\Suricata\rules\tor.rules 19/1/2022 -- 15:52:07 - - 44 rule files processed. 23850 rules successfully loaded, 0 rules failed 19/1/2022 -- 15:52:07 - - Threshold config parsed: 0 rule(s) found 19/1/2022 -- 15:52:07 - - using shared mpm ctx' for tcp-packet 19/1/2022 -- 15:52:07 - - using shared mpm ctx' for tcp-stream 19/1/2022 -- 15:52:07 - - using shared mpm ctx' for udp-packet 19/1/2022 -- 15:52:07 - - using shared mpm ctx' for other-ip 19/1/2022 -- 15:52:07 - - 23853 signatures processed. 1289 are IP-only rules, 4139 are inspecting packet payload, 18400 inspect application layer, 0 are decoder event only 19/1/2022 -- 15:52:07 - - building signature grouping structure, stage 1: preprocessing rules... complete 19/1/2022 -- 15:52:07 - - TCP toserver: 41 port groups, 39 unique SGH's, 2 copies 19/1/2022 -- 15:52:07 - - TCP toclient: 21 port groups, 21 unique SGH's, 0 copies 19/1/2022 -- 15:52:07 - - UDP toserver: 41 port groups, 38 unique SGH's, 3 copies 19/1/2022 -- 15:52:07 - - UDP toclient: 21 port groups, 17 unique SGH's, 4 copies 19/1/2022 -- 15:52:07 - - OTHER toserver: 254 proto groups, 3 unique SGH's, 251 copies 19/1/2022 -- 15:52:07 - - OTHER toclient: 254 proto groups, 0 unique SGH's, 254 copies 19/1/2022 -- 15:52:16 - - Unique rule groups: 118 19/1/2022 -- 15:52:16 - - Builtin MPM "toserver TCP packet": 26 19/1/2022 -- 15:52:16 - - Builtin MPM "toclient TCP packet": 20 19/1/2022 -- 15:52:16 - - Builtin MPM "toserver TCP stream": 30 19/1/2022 -- 15:52:16 - - Builtin MPM "toclient TCP stream": 21 19/1/2022 -- 15:52:16 - - Builtin MPM "toserver UDP packet": 38 19/1/2022 -- 15:52:16 - - Builtin MPM "toclient UDP packet": 16 19/1/2022 -- 15:52:16 - - Builtin MPM "other IP packet": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_uri (http)": 8 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_uri (http2)": 8 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_raw_uri (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_raw_uri (http2)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_request_line (http)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_client_body (http)": 5 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_response_line (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_header (http)": 8 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_header (http)": 8 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_header_names (http)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_header_names (http)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_accept (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_accept (http2)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_accept_enc (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_accept_enc (http2)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_accept_lang (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_accept_lang (http2)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_referer (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_referer (http2)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_content_len (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_content_len (http2)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_content_len (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_content_len (http2)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_content_type (http)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_content_type (http2)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_content_type (http)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_content_type (http2)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_protocol (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_protocol (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_start (http)": 4 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_start (http)": 4 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_raw_header (http)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_raw_header (http)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_method (http)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_method (http2)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_cookie (http)": 3 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_cookie (http)": 3 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_cookie (http2)": 3 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_cookie (http2)": 3 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_user_agent (http)": 6 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_user_agent (http2)": 6 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_host (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_raw_host (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver http_raw_host (http2)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_stat_code (http)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient http_stat_code (http2)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver dns_query (dns)": 4 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver tls.sni (tls)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient tls.cert_issuer (tls)": 5 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient tls.cert_subject (tls)": 2 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient tls.cert_serial (tls)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver ssh.proto (ssh)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient ssh.proto (ssh)": 1 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver file_data (smtp)": 7 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient file_data (http)": 7 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver file_data (smb)": 7 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient file_data (smb)": 7 19/1/2022 -- 15:52:16 - - AppLayer MPM "toserver file_data (http2)": 7 19/1/2022 -- 15:52:16 - - AppLayer MPM "toclient file_data (http2)": 7 19/1/2022 -- 15:52:17 - - AutoFP mode using "Hash" flow load balancer 19/1/2022 -- 15:52:17 - - using 1 flow manager threads 19/1/2022 -- 15:52:17 - - using 1 flow recycler threads 19/1/2022 -- 15:52:17 - - all 10 packet processing threads, 4 management threads initialized, engine started. 19/1/2022 -- 15:52:43 - - [ERRCODE: SC_ERR_WINDIVERT_GENERIC(312)] - WinDivertOpen failed, error 87 (0x00000057): Paramètre incorrect. The WinDivert packet filter string is invalid. 19/1/2022 -- 15:52:43 - - [ERRCODE: SC_ERR_FATAL(171)] - thread TX#00 failed