diff --git a/Suricata.xml b/Suricata.xml
index d708501..a5b2222 100644
--- a/Suricata.xml
+++ b/Suricata.xml
@@ -147,6 +147,27 @@
+
+
+
+ 86601
+ ^SURICATA STREAM 3way handshake SYNACK with wrong ack$
+ Suricata: Alert - 3way handshake SYNACK with wrong ack
+ no_full_log
+
+
+
+
+
+
+
+ 100534
+ flow.src_ip
+ Suricata: Alert - Multiple 3way handshake SYNACK with wrong ack
+ no_full_log
+
+
+
@@ -296,7 +317,7 @@
86601
^SURICATA SMB too many transactions$
- (10.171.101.36|10.172.101.113)
+ (10.171.101.36|10.172.101.113|10.172.101.114)
Suricata: Alert - $(alert.signature)
no_full_log
@@ -307,7 +328,7 @@
86601
^SURICATA SMB too many transactions$
- (10.171.101.36|10.172.101.113)
+ (10.171.101.36|10.172.101.113|10.172.101.114)
Suricata: Alert - $(alert.signature)
no_full_log
@@ -640,7 +661,7 @@
-
+
86601
DoH
Suricata : DNS over HTTPS
@@ -659,4 +680,34 @@
no_full_log
+
+
+
+
+
+ 86601
+ SURICATA QUIC error on data
+ Suricata : QUIC ERROR
+ no_full_log
+
+
+
+
+
+
+ 86601
+ SURICATA QUIC failed decrypt
+ Suricata : QUIC FAILED
+ no_full_log
+
+
+
+
+
+
+ 86601
+ Informational
+ Suricata : Alertes informationnel
+ no_full_log
+
\ No newline at end of file
diff --git a/brut-force.xml b/brut-force.xml
index 529ed11..c90abe0 100644
--- a/brut-force.xml
+++ b/brut-force.xml
@@ -1,6 +1,6 @@
-
+
60122
win.eventdata.ipAddress
Brut force
@@ -18,7 +18,7 @@
-
+
win.eventdata.ipAddress
60105
Brut force
diff --git a/fim-fs17101.xml b/fim-fs17101.xml
index 1a5bf63..f5d44c2 100644
--- a/fim-fs17101.xml
+++ b/fim-fs17101.xml
@@ -1,4 +1,4 @@
-
+
@@ -10,9 +10,27 @@
+
+
+
+ 100100
+ .tmp$
+ Filtre modif fichier temporaire
+
+
+
+
+
+
+ 100100
+ Zone.Identifier$
+ Filtre modif fichier temporaire
+
+
+
-
+
100100
^4663$
Alerte fichier modifié
@@ -22,7 +40,7 @@
-
+
100100
^4659$
Alerte fichier supprimé
@@ -32,7 +50,7 @@
-
+
100100
Écriture données (ou ajout fichier)
Alerte fichier Créé
@@ -42,11 +60,29 @@
-
+
- 100102
+ 100103
win.eventdata.subjectUserName
- Fichier supprimer en masse
+ Fichier créer en masse - Chiffrage ?
+
+
+
+
+
+
+ 100104
+ win.eventdata.subjectUserName
+ Fichier supprime en masse - Chiffrage ?
+
+
+
+
+
+
+
+ 8215
+ Tentative de création de fichier avec extension bloqué
diff --git a/fortigate.xml b/fortigate.xml
new file mode 100644
index 0000000..e4bfc0f
--- /dev/null
+++ b/fortigate.xml
@@ -0,0 +1,65 @@
+
+
+
+
+ fortigate
+ lan
+ wan
+ Fortigate: trafic lan vers wan
+
+
+
+
+
+ 100250
+ dstip=10\.|dstip=192\.168\.|dstip=172\.1[6-9]\.|dstip=172\.2[0-9]\.|dstip=172\.3[01]\.
+ Fortigate: destination IP publique confirmee
+
+
+
+
+ 100251
+ ^[1-9]\d{8}$
+ Fortigate: Large outbound transfer ($(sentbyte) bytes) from $(srcip) to $(dstip)
+
+
+
+
+ 100251
+ ^[5-9]\d{8}$
+ Fortigate: Large outbound transfer ($(sentbyte) bytes) from $(srcip) to $(dstip)
+
+
+
+
+ 100251
+ ^\d{10,}$
+ CRITICAL - Fortigate: Massive outbound transfer 1GB from $(srcip) to $(dstip)
+
+
+
+
+ 100252
+ Fortigate: Repeated large transfers from $(srcip) - possible large exfiltration in progress
+
+
+
+
+
+
+
+ 100254
+
+ Fortigate: Large transfers from $(srcip) in quiet hour - possible large exfiltration
+
+
+
+
+
+
+ 100251
+ ^\d{11,}$
+ CRITICAL - Fortigate: Massive outbound transfer 10GB from $(srcip) to $(dstip)
+
+
+
diff --git a/linux.xml b/linux.xml
new file mode 100644
index 0000000..80dc3e0
--- /dev/null
+++ b/linux.xml
@@ -0,0 +1,22 @@
+
+
+
+
+
+
+ 2904
+ ^status half-configured$
+ Filtre bruit : dpkg linux (maj)
+ no_full_log
+
+
+
+
+
+
+ 2902
+ ^status installed$
+ Filtre bruit : dpkg linux (maj)
+ no_full_log
+
+
\ No newline at end of file
diff --git a/registre-windows.xml b/registre-windows.xml
new file mode 100644
index 0000000..9f33138
--- /dev/null
+++ b/registre-windows.xml
@@ -0,0 +1,194 @@
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\VSS\\Diag
+ FP Suppressed - VSS Diag registry keys modified during backup/snapshot operation
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\VSS\\
+ BACKUPCOMPLETE|BACKUPSHUTDOWN|BACKUPSTART|PREPAREBACKUP|POSTBACKUP|BackupComplete
+ FP Suppressed - VSS backup lifecycle registry value changed (normal backup operation)
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate
+ FP Suppressed - Windows Update registry keys (normal update activity)
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Component Based Servicing
+ FP Suppressed - CBS registry changes during Windows Update
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SoftwareProtectionPlatform
+ FP Suppressed - Software Protection Platform registry (licensing checks, normal)
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Perflib
+ FP Suppressed - Performance Library registry keys (updated continuously by OS)
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\PerfHost
+ FP Suppressed - PerfHost service registry (performance counter host, normal activity)
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Tcpip\\Parameters\\Interfaces
+ LeaseObtainedTime|LeaseTerminatesTime|T1|T2|DhcpIPAddress|DhcpNameServer|DhcpSubnetMask|DhcpDefaultGateway
+ FP Suppressed - DHCP lease renewal registry update (normal network operation)
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog
+ MajorVersion|MinorVersion|CurrentSize|LastWriteTime|Flags
+ FP Suppressed - EventLog metadata registry keys (updated on every log write)
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Signature Updates
+ FP Suppressed - Windows Defender signature update registry changes
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows Defender\\Scans
+ FP Suppressed - Windows Defender scan state registry keys
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\AutoEnrollment
+ FP Suppressed - Certificate auto-enrollment registry update (normal AD/PKI operation)
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates
+ FP Suppressed - System certificate store registry changes (CRL updates, renewals)
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks
+ LastRunTime|NextRunTime|LastSuccessfulRunTime
+ FP Suppressed - Task Scheduler runtime timestamps (updated on every task execution)
+
+
+
+
+
+
+
+
+ syscheck_registry
+ HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\W32Time
+ LastSyncTime|ClockAdjustment|PhaseOffset|ClockRate
+ FP Suppressed - W32Time NTP synchronization registry update (normal time sync)
+
+
+
\ No newline at end of file
diff --git a/unifi-rules.xml b/unifi-rules.xml
index 941dcba..7f7664d 100644
--- a/unifi-rules.xml
+++ b/unifi-rules.xml
@@ -117,10 +117,10 @@
-
+
unifi
failure
- UniFi WiFi: assoc/auth failure sta=$(sta_mac) vap=$(vap) ap=$(device) site=$(site) wpa_auth_failures=$(wpa_auth_failures)
+ UniFi WiFi: assoc/auth failure sta=$(mac) vap=$(vap) ap=$(device) site=$(site) wpa_auth_failures=$(wpa_auth_failures)
@@ -128,7 +128,7 @@
unifi
disassociated
- UniFi WiFi: STA $(wifi_event) sta=$(sta_mac) vap=$(vap) ap=$(device) site=$(site)
+ UniFi WiFi: STA $(wifi_event) sta=$(mac) vap=$(vap) ap=$(device) site=$(site)
@@ -136,7 +136,7 @@
unifi
deauthenticated
- UniFi WiFi: STA $(wifi_event) sta=$(sta_mac) vap=$(vap) ap=$(device) site=$(site)
+ UniFi WiFi: STA $(wifi_event) sta=$(mac) vap=$(vap) ap=$(device) site=$(site)
@@ -144,8 +144,8 @@
100430
site
- sta_mac
- UniFi WiFi: repeated auth failures (5x/2min) sta=$(sta_mac) site=$(site) vap=$(vap)
+ mac
+ UniFi WiFi: repeated auth failures (5x/2min) sta=$(mac) site=$(site) vap=$(vap)
@@ -173,3 +173,21 @@
UniFi WiFi: repeated stuck beacon/reset (3x/10min) site=$(site)
+
+
+
+
+
+ unifi
+ dvlan rate limited
+ UniFi WiFi: limitation bande passante
+
+
+
+
+
+ 100450
+ mac
+ UniFi WiFi: limitation bande passant répété même client - pb réseau ?
+
+
diff --git a/web-attack.xml b/web-attack.xml
new file mode 100644
index 0000000..3cadfc0
--- /dev/null
+++ b/web-attack.xml
@@ -0,0 +1,31 @@
+
+
+
+
+
+
+
+ 31530
+ 10.172.253.99
+ Filtrage DDOS Zabbix
+ no_full_log
+
+
+
+
+
+ 31530
+ /zabbix
+ Filtrage DDOS Zabbix
+ no_full_log
+
+
+
+
+
+ 31533
+ 10.172.253.99
+ Filtrage DDOS Zabbix
+ no_full_log
+
+