diff --git a/Suricata.xml b/Suricata.xml index d708501..a5b2222 100644 --- a/Suricata.xml +++ b/Suricata.xml @@ -147,6 +147,27 @@ + + + + 86601 + ^SURICATA STREAM 3way handshake SYNACK with wrong ack$ + Suricata: Alert - 3way handshake SYNACK with wrong ack + no_full_log + + + + + + + + 100534 + flow.src_ip + Suricata: Alert - Multiple 3way handshake SYNACK with wrong ack + no_full_log + + + @@ -296,7 +317,7 @@ 86601 ^SURICATA SMB too many transactions$ - (10.171.101.36|10.172.101.113) + (10.171.101.36|10.172.101.113|10.172.101.114) Suricata: Alert - $(alert.signature) no_full_log @@ -307,7 +328,7 @@ 86601 ^SURICATA SMB too many transactions$ - (10.171.101.36|10.172.101.113) + (10.171.101.36|10.172.101.113|10.172.101.114) Suricata: Alert - $(alert.signature) no_full_log @@ -640,7 +661,7 @@ - + 86601 DoH Suricata : DNS over HTTPS @@ -659,4 +680,34 @@ no_full_log + + + + + + 86601 + SURICATA QUIC error on data + Suricata : QUIC ERROR + no_full_log + + + + + + + 86601 + SURICATA QUIC failed decrypt + Suricata : QUIC FAILED + no_full_log + + + + + + + 86601 + Informational + Suricata : Alertes informationnel + no_full_log + \ No newline at end of file diff --git a/brut-force.xml b/brut-force.xml index 529ed11..c90abe0 100644 --- a/brut-force.xml +++ b/brut-force.xml @@ -1,6 +1,6 @@ - + 60122 win.eventdata.ipAddress Brut force @@ -18,7 +18,7 @@ - + win.eventdata.ipAddress 60105 Brut force diff --git a/fim-fs17101.xml b/fim-fs17101.xml index 1a5bf63..f5d44c2 100644 --- a/fim-fs17101.xml +++ b/fim-fs17101.xml @@ -1,4 +1,4 @@ - + @@ -10,9 +10,27 @@ + + + + 100100 + .tmp$ + Filtre modif fichier temporaire + + + + + + + 100100 + Zone.Identifier$ + Filtre modif fichier temporaire + + + - + 100100 ^4663$ Alerte fichier modifié @@ -22,7 +40,7 @@ - + 100100 ^4659$ Alerte fichier supprimé @@ -32,7 +50,7 @@ - + 100100 Écriture données (ou ajout fichier) Alerte fichier Créé @@ -42,11 +60,29 @@ - + - 100102 + 100103 win.eventdata.subjectUserName - Fichier supprimer en masse + Fichier créer en masse - Chiffrage ? + + + + + + + 100104 + win.eventdata.subjectUserName + Fichier supprime en masse - Chiffrage ? + + + + + + + + 8215 + Tentative de création de fichier avec extension bloqué diff --git a/fortigate.xml b/fortigate.xml new file mode 100644 index 0000000..e4bfc0f --- /dev/null +++ b/fortigate.xml @@ -0,0 +1,65 @@ + + + + + fortigate + lan + wan + Fortigate: trafic lan vers wan + + + + + + 100250 + dstip=10\.|dstip=192\.168\.|dstip=172\.1[6-9]\.|dstip=172\.2[0-9]\.|dstip=172\.3[01]\. + Fortigate: destination IP publique confirmee + + + + + 100251 + ^[1-9]\d{8}$ + Fortigate: Large outbound transfer ($(sentbyte) bytes) from $(srcip) to $(dstip) + + + + + 100251 + ^[5-9]\d{8}$ + Fortigate: Large outbound transfer ($(sentbyte) bytes) from $(srcip) to $(dstip) + + + + + 100251 + ^\d{10,}$ + CRITICAL - Fortigate: Massive outbound transfer 1GB from $(srcip) to $(dstip) + + + + + 100252 + Fortigate: Repeated large transfers from $(srcip) - possible large exfiltration in progress + + + + + + + + 100254 + + Fortigate: Large transfers from $(srcip) in quiet hour - possible large exfiltration + + + + + + + 100251 + ^\d{11,}$ + CRITICAL - Fortigate: Massive outbound transfer 10GB from $(srcip) to $(dstip) + + + diff --git a/linux.xml b/linux.xml new file mode 100644 index 0000000..80dc3e0 --- /dev/null +++ b/linux.xml @@ -0,0 +1,22 @@ + + + + + + + 2904 + ^status half-configured$ + Filtre bruit : dpkg linux (maj) + no_full_log + + + + + + + 2902 + ^status installed$ + Filtre bruit : dpkg linux (maj) + no_full_log + + \ No newline at end of file diff --git a/registre-windows.xml b/registre-windows.xml new file mode 100644 index 0000000..9f33138 --- /dev/null +++ b/registre-windows.xml @@ -0,0 +1,194 @@ + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\VSS\\Diag + FP Suppressed - VSS Diag registry keys modified during backup/snapshot operation + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\VSS\\ + BACKUPCOMPLETE|BACKUPSHUTDOWN|BACKUPSTART|PREPAREBACKUP|POSTBACKUP|BackupComplete + FP Suppressed - VSS backup lifecycle registry value changed (normal backup operation) + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate + FP Suppressed - Windows Update registry keys (normal update activity) + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Component Based Servicing + FP Suppressed - CBS registry changes during Windows Update + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SoftwareProtectionPlatform + FP Suppressed - Software Protection Platform registry (licensing checks, normal) + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib + FP Suppressed - Performance Library registry keys (updated continuously by OS) + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfHost + FP Suppressed - PerfHost service registry (performance counter host, normal activity) + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Interfaces + LeaseObtainedTime|LeaseTerminatesTime|T1|T2|DhcpIPAddress|DhcpNameServer|DhcpSubnetMask|DhcpDefaultGateway + FP Suppressed - DHCP lease renewal registry update (normal network operation) + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog + MajorVersion|MinorVersion|CurrentSize|LastWriteTime|Flags + FP Suppressed - EventLog metadata registry keys (updated on every log write) + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Signature Updates + FP Suppressed - Windows Defender signature update registry changes + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Scans + FP Suppressed - Windows Defender scan state registry keys + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\AutoEnrollment + FP Suppressed - Certificate auto-enrollment registry update (normal AD/PKI operation) + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates + FP Suppressed - System certificate store registry changes (CRL updates, renewals) + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks + LastRunTime|NextRunTime|LastSuccessfulRunTime + FP Suppressed - Task Scheduler runtime timestamps (updated on every task execution) + + + + + + + + + syscheck_registry + HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W32Time + LastSyncTime|ClockAdjustment|PhaseOffset|ClockRate + FP Suppressed - W32Time NTP synchronization registry update (normal time sync) + + + \ No newline at end of file diff --git a/unifi-rules.xml b/unifi-rules.xml index 941dcba..7f7664d 100644 --- a/unifi-rules.xml +++ b/unifi-rules.xml @@ -117,10 +117,10 @@ - + unifi failure - UniFi WiFi: assoc/auth failure sta=$(sta_mac) vap=$(vap) ap=$(device) site=$(site) wpa_auth_failures=$(wpa_auth_failures) + UniFi WiFi: assoc/auth failure sta=$(mac) vap=$(vap) ap=$(device) site=$(site) wpa_auth_failures=$(wpa_auth_failures) @@ -128,7 +128,7 @@ unifi disassociated - UniFi WiFi: STA $(wifi_event) sta=$(sta_mac) vap=$(vap) ap=$(device) site=$(site) + UniFi WiFi: STA $(wifi_event) sta=$(mac) vap=$(vap) ap=$(device) site=$(site) @@ -136,7 +136,7 @@ unifi deauthenticated - UniFi WiFi: STA $(wifi_event) sta=$(sta_mac) vap=$(vap) ap=$(device) site=$(site) + UniFi WiFi: STA $(wifi_event) sta=$(mac) vap=$(vap) ap=$(device) site=$(site) @@ -144,8 +144,8 @@ 100430 site - sta_mac - UniFi WiFi: repeated auth failures (5x/2min) sta=$(sta_mac) site=$(site) vap=$(vap) + mac + UniFi WiFi: repeated auth failures (5x/2min) sta=$(mac) site=$(site) vap=$(vap) @@ -173,3 +173,21 @@ UniFi WiFi: repeated stuck beacon/reset (3x/10min) site=$(site) + + + + + + unifi + dvlan rate limited + UniFi WiFi: limitation bande passante + + + + + + 100450 + mac + UniFi WiFi: limitation bande passant répété même client - pb réseau ? + + diff --git a/web-attack.xml b/web-attack.xml new file mode 100644 index 0000000..3cadfc0 --- /dev/null +++ b/web-attack.xml @@ -0,0 +1,31 @@ + + + + + + + + 31530 + 10.172.253.99 + Filtrage DDOS Zabbix + no_full_log + + + + + + 31530 + /zabbix + Filtrage DDOS Zabbix + no_full_log + + + + + + 31533 + 10.172.253.99 + Filtrage DDOS Zabbix + no_full_log + +