ridzimeko / TA Suricata Ruleset

0 likes
0 forks
1 files
Last active 1787098967
1 # --- SSH SCAN & BRUTEFORCE ---
2 alert ssh any any -> $HOME_NET 22 (msg:"ET SCAN LibSSH Based Frequent SSH Connections Likely BruteForce Attack"; flow:established,to_server; content:"SSH-"; content:"libssh"; within:20; threshold: type both, count 5, seconds 30, track by_src; classtype:attempted-admin; sid:2006546; rev:9; metadata:created_at 2010_07_30, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)
3 alert ssh any any -> $HOME_NET any (msg:"ET SCAN SSH BruteForce Tool with fake PUTTY version"; flow:established,to_server; ssh_proto; content:"PUTTY"; threshold: type limit, track by_src, count 1, seconds 30; classtype:network-scan; sid:2019876; rev:6; metadata:created_at 2014_12_05, confidence Medium, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
4 alert tcp $EXTERNAL_NET any -> $HOME_NET 22 (msg:"SSH Brute Force Connection Pattern"; flow:to_server; flags:S,12; threshold: type both, track by_src, count 20, seconds 120; reference:url,en.wikipedia.org/wiki/Brute_force_attack; classtype:attempted-recon; sid:2001219; rev:20; metadata:created_at 2010_07_30, confidence Medium, signature_severity Informational, updated_at 2019_07_26;)
5
6 # --- PORT SCANNING RULES ---
7 # SCAN SYN (GENERAL)
8 alert tcp any any -> $HOME_NET any (msg:"SCAN Nmap SYN scan detected"; flags:S,12; threshold: type threshold, track by_src, count 1000, seconds 10; classtype:attempted-recon; sid:1000001; rev:1;)
9
10 # SCAN OS
Newer Older