diff --git a/Suricata.xml b/Suricata.xml index f345692..2973770 100644 --- a/Suricata.xml +++ b/Suricata.xml @@ -255,10 +255,20 @@ + + + + 86601 + ^SURICATA UDPv6 invalid checksum$ + Suricata: Alert - $(alert.signature) + no_full_log + + + - - 86601 + + 100580 ^SURICATA UDPv6 invalid checksum$ 5353 Suricata: Alert - $(alert.signature) @@ -268,8 +278,8 @@ - - 86601 + + 100580 ^SURICATA UDPv6 invalid checksum$ flow.src_ip Suricata: Alert - IPv6 UDP malformed packet flooding (repeated invalid checksum) @@ -321,7 +331,7 @@ - + 86601 ^ET INFO SMB2 NT Create AndX Request For an Executable File$ Suricata: Filtrage executable file SMB @@ -332,8 +342,8 @@ - - 100592 + + 100600 .+ Suricata: Filtrage executable file SMB no_full_log @@ -344,8 +354,8 @@ - - 100593 + + 100600 (?i)Systeme.*\.exe Suricata: Known business software (Sphinx) executed from SMB share @@ -356,9 +366,8 @@ - - 100593 - ^ET INFO SMB2 NT Create AndX Request For an Executable File$ + + 100600 (?i)\.(pdf|docx?|xlsx?|pptx?|txt|jpe?g|png|gif|csv|zip|rar) Suricata: Fichier executable dans dossier partagé @@ -369,9 +378,8 @@ - + - + 86601 ET INFO SMB2 NT Create AndX Request For a DLL File - Possible Lateral Movement + Suricata : SMB DLL access + no_full_log + + + + + + + + 100610 10.171.101.36 Suricata : SMB DLL access on file server (often legitimate shared app/library) no_full_log - + - - 86601 - ET INFO SMB2 NT Create AndX Request For a DLL File - Possible Lateral Movement + + 100610 10.171.101.36 Suricata : SMB DLL access on file server (often legitimate shared app/library) no_full_log @@ -405,7 +422,7 @@ - + 86601 SURICATA SMB file overlap Suricata: SMB file overlap (normal SMB read behaviour) @@ -414,34 +431,10 @@ - + + - - 86601 - DoH - Suricata : DNS over HTTPS - no_full_log - - - - - - - 100600 - ^10\.172\.253\. - Suricata DNS over HTTPS VLAN ADMINSYS - - T1071.004 - - no_full_log - - - - - - - - + 86601 SURICATA STREAM bad window update Suricata : Network/offloading/capture noiseS @@ -451,8 +444,8 @@ - - 100610 + + 100630 src_ip High rate of TCP bad window updates from same host (possible local network stack/capture issue) @@ -467,7 +460,7 @@ - + 86601 SURICATA UDPv4 invalid checksum Suricata : UDPv4 invalid checksum - likely NIC offload/SPAN capture noise (often QUIC) @@ -477,8 +470,8 @@ - - 100620 + + 100640 flow.src_ip High rate of UDPv4 invalid checksum from same host (possible malformed UDP flood / DoS) no_full_log @@ -488,7 +481,7 @@ - + 86601 @@ -507,8 +500,8 @@ - - 100630 + + 100650 src_ip @@ -525,7 +518,7 @@ - + 86601 SURICATA STREAM ESTABLISHED packet out of window Suricata: TCP stream out-of-window (likely retransmission/capture/offload) - noise reduction @@ -537,8 +530,8 @@ - - 100632 + + 100660 flow.src_ip Suricata: Repeated TCP out-of-window packets from same host (possible evasion / unstable TCP stack / capture issue) @@ -548,12 +541,35 @@ + + + + 100660 + 8007 + + Ignore Suricata out of window between PBS during replication + no_full_log + + + + + + + + 100660 + 8007 + + Ignore Suricata out of window between PBS during replication + no_full_log + + + - + 86601 ET INFO Session Traversal Utilities for NAT (STUN Binding Response) Suricata: STUN binding response (likely WebRTC/VoIP) @@ -563,8 +579,8 @@ - - 100640 + + 100670 192\.168\.12\.* Suricata: STUN binding response (likely WebRTC/VoIP) - noise reduction no_full_log @@ -573,8 +589,8 @@ - - 100640 + + 100670 10\.17[0-9]\.[1|2]\. Suricata: STUN binding response (likely WebRTC/VoIP) - noise reduction no_full_log @@ -585,8 +601,8 @@ - - 100640 + + 100670 flow.src_ip Suricata: Abnormal STUN activity burst (possible tunneling / unauthorized VoIP / P2P) @@ -596,12 +612,23 @@ + + + + + 86601 + SURICATA STREAM ESTABLISHED invalid ack + Suricata invalid ack + no_full_log + + + + - - 86601 - SURICATA STREAM ESTABLISHED invalid ack + + 100680 8007 Ignore Suricata invalid ack between PBS during replication @@ -611,9 +638,8 @@ - - 86601 - SURICATA STREAM ESTABLISHED invalid ack + + 100680 8007 Ignore Suricata invalid ack between PBS during replication @@ -622,27 +648,26 @@ - - - - 86601 - SURICATA STREAM ESTABLISHED packet out of window - 8007 - - Ignore Suricata out of window between PBS during replication - no_full_log - - - - - - - 86601 - SURICATA STREAM ESTABLISHED packet out of window - 8007 - - Ignore Suricata out of window between PBS during replication - no_full_log - + + + + + 86601 + DoH + Suricata : DNS over HTTPS + no_full_log + + + + + 100700 + ^10\.172\.253\. + Suricata DNS over HTTPS VLAN ADMINSYS + + T1071.004 + + no_full_log + + \ No newline at end of file