diff --git a/Suricata.xml b/Suricata.xml
index f345692..2973770 100644
--- a/Suricata.xml
+++ b/Suricata.xml
@@ -255,10 +255,20 @@
+
+
+
+ 86601
+ ^SURICATA UDPv6 invalid checksum$
+ Suricata: Alert - $(alert.signature)
+ no_full_log
+
+
+
-
- 86601
+
+ 100580
^SURICATA UDPv6 invalid checksum$
5353
Suricata: Alert - $(alert.signature)
@@ -268,8 +278,8 @@
-
- 86601
+
+ 100580
^SURICATA UDPv6 invalid checksum$
flow.src_ip
Suricata: Alert - IPv6 UDP malformed packet flooding (repeated invalid checksum)
@@ -321,7 +331,7 @@
-
+
86601
^ET INFO SMB2 NT Create AndX Request For an Executable File$
Suricata: Filtrage executable file SMB
@@ -332,8 +342,8 @@
-
- 100592
+
+ 100600
.+
Suricata: Filtrage executable file SMB
no_full_log
@@ -344,8 +354,8 @@
-
- 100593
+
+ 100600
(?i)Systeme.*\.exe
Suricata: Known business software (Sphinx) executed from SMB share
@@ -356,9 +366,8 @@
-
- 100593
- ^ET INFO SMB2 NT Create AndX Request For an Executable File$
+
+ 100600
(?i)\.(pdf|docx?|xlsx?|pptx?|txt|jpe?g|png|gif|csv|zip|rar)
Suricata: Fichier executable dans dossier partagé
@@ -369,9 +378,8 @@
-
+
-
+
86601
ET INFO SMB2 NT Create AndX Request For a DLL File - Possible Lateral Movement
+ Suricata : SMB DLL access
+ no_full_log
+
+
+
+
+
+
+
+ 100610
10.171.101.36
Suricata : SMB DLL access on file server (often legitimate shared app/library)
no_full_log
-
+
-
- 86601
- ET INFO SMB2 NT Create AndX Request For a DLL File - Possible Lateral Movement
+
+ 100610
10.171.101.36
Suricata : SMB DLL access on file server (often legitimate shared app/library)
no_full_log
@@ -405,7 +422,7 @@
-
+
86601
SURICATA SMB file overlap
Suricata: SMB file overlap (normal SMB read behaviour)
@@ -414,34 +431,10 @@
-
+
+
-
- 86601
- DoH
- Suricata : DNS over HTTPS
- no_full_log
-
-
-
-
-
-
- 100600
- ^10\.172\.253\.
- Suricata DNS over HTTPS VLAN ADMINSYS
-
- T1071.004
-
- no_full_log
-
-
-
-
-
-
-
-
+
86601
SURICATA STREAM bad window update
Suricata : Network/offloading/capture noiseS
@@ -451,8 +444,8 @@
-
- 100610
+
+ 100630
src_ip
High rate of TCP bad window updates from same host (possible local network stack/capture issue)
@@ -467,7 +460,7 @@
-
+
86601
SURICATA UDPv4 invalid checksum
Suricata : UDPv4 invalid checksum - likely NIC offload/SPAN capture noise (often QUIC)
@@ -477,8 +470,8 @@
-
- 100620
+
+ 100640
flow.src_ip
High rate of UDPv4 invalid checksum from same host (possible malformed UDP flood / DoS)
no_full_log
@@ -488,7 +481,7 @@
-
+
86601
@@ -507,8 +500,8 @@
-
- 100630
+
+ 100650
src_ip
@@ -525,7 +518,7 @@
-
+
86601
SURICATA STREAM ESTABLISHED packet out of window
Suricata: TCP stream out-of-window (likely retransmission/capture/offload) - noise reduction
@@ -537,8 +530,8 @@
-
- 100632
+
+ 100660
flow.src_ip
Suricata: Repeated TCP out-of-window packets from same host (possible evasion / unstable TCP stack / capture issue)
@@ -548,12 +541,35 @@
+
+
+
+ 100660
+ 8007
+
+ Ignore Suricata out of window between PBS during replication
+ no_full_log
+
+
+
+
+
+
+
+ 100660
+ 8007
+
+ Ignore Suricata out of window between PBS during replication
+ no_full_log
+
+
+
-
+
86601
ET INFO Session Traversal Utilities for NAT (STUN Binding Response)
Suricata: STUN binding response (likely WebRTC/VoIP)
@@ -563,8 +579,8 @@
-
- 100640
+
+ 100670
192\.168\.12\.*
Suricata: STUN binding response (likely WebRTC/VoIP) - noise reduction
no_full_log
@@ -573,8 +589,8 @@
-
- 100640
+
+ 100670
10\.17[0-9]\.[1|2]\.
Suricata: STUN binding response (likely WebRTC/VoIP) - noise reduction
no_full_log
@@ -585,8 +601,8 @@
-
- 100640
+
+ 100670
flow.src_ip
Suricata: Abnormal STUN activity burst (possible tunneling / unauthorized VoIP / P2P)
@@ -596,12 +612,23 @@
+
+
+
+
+ 86601
+ SURICATA STREAM ESTABLISHED invalid ack
+ Suricata invalid ack
+ no_full_log
+
+
+
+
-
- 86601
- SURICATA STREAM ESTABLISHED invalid ack
+
+ 100680
8007
Ignore Suricata invalid ack between PBS during replication
@@ -611,9 +638,8 @@
-
- 86601
- SURICATA STREAM ESTABLISHED invalid ack
+
+ 100680
8007
Ignore Suricata invalid ack between PBS during replication
@@ -622,27 +648,26 @@
-
-
-
- 86601
- SURICATA STREAM ESTABLISHED packet out of window
- 8007
-
- Ignore Suricata out of window between PBS during replication
- no_full_log
-
-
-
-
-
-
- 86601
- SURICATA STREAM ESTABLISHED packet out of window
- 8007
-
- Ignore Suricata out of window between PBS during replication
- no_full_log
-
+
+
+
+
+ 86601
+ DoH
+ Suricata : DNS over HTTPS
+ no_full_log
+
+
+
+
+ 100700
+ ^10\.172\.253\.
+ Suricata DNS over HTTPS VLAN ADMINSYS
+
+ T1071.004
+
+ no_full_log
+
+
\ No newline at end of file