|
77 | 77 | @ [email protected]_type == 7 || sctp.chunk_type == 8 || sctp.chunk_type == 14@[65535,65535,14392][0,0,0] |
78 | 78 | @ [email protected]_type == 4 || sctp.chunk_type == 5@[52428,52428,65535][0,0,0] |
79 | 79 | @ [email protected]_type == 3@[59367,58339,59367][0,0,0] |
80 | | -@Bad [email protected]@[0,0,0][65535,24415,24415] |
81 | | -@HSRP State [email protected] != 8 && hsrp.state != 16@[0,0,0][65535,63222,0] |
82 | | -@Spanning Tree Topology [email protected] == 0x80@[0,0,0][65535,63222,0] |
83 | | -@OSPF State [email protected] != 1@[0,0,0][65535,63222,0] |
84 | | -@ICMP [email protected] eq 3 || icmp.type eq 4 || icmp.type eq 11@[0,0,0][0,65535,3598] |
85 | | -@ARP@arp@[54998,59624,65535][0,0,0] |
86 | | -@ICMP@icmp@[49858,49858,65535][0,0,0] |
87 | | -@TCP [email protected] eq 1@[37008,0,0][65535,63222,32896] |
88 | | -@Low [email protected] < 5@[37008,0,0][65535,65535,65535] |
89 | | -@Checksum [email protected]_bad==1 || ip.checksum_bad==1 || tcp.checksum_bad || udp.checksum_bad@[0,0,0][65535,24415,24415] |
90 | | -@SMB@smb || nbss || nbns || nbipx || ipxsap || netbios@[65535,64250,39321][0,0,0] |
91 | | -@HTTP@http || tcp.port == 80@[36237,65535,32639][0,0,0] |
92 | | -@IPX@ipx || stp@[65535,58339,58853][0,0,0] |
93 | | -@DCERPC@dcerpc@[51143,38807,65535][0,0,0] |
94 | | -@Routing@hsrp || eigrp || ospf || bgp || cdp || vrrp || gvrp || igmp || ismp@[65535,62451,54998][0,0,0] |
95 | | -@TCP SYN/ [email protected] & 0x02 || tcp.flags.fin == 1@[41120,41120,41120][0,0,0] |
96 | | -@TCP@tcp@[59367,59110,65535][0,0,0] |
97 | | -@UDP@udp@[28784,57568,65535][0,0,0] |
98 | | -@Broadcast@eth[0] & 1@[65535,65535,65535][32896,32896,32896] |
| 80 | +@Bad [email protected] && !tcp.analysis.window_update && !tcp.analysis.keep_alive && !tcp.analysis.keep_alive_ack@[4626,10023,11822][63479,34695,34695] |
| 81 | +@HSRP State [email protected] != 8 && hsrp.state != 16@[4626,10023,11822][65535,64764,40092] |
| 82 | +@Spanning Tree Topology [email protected] == 0x80@[4626,10023,11822][65535,64764,40092] |
| 83 | +@OSPF State [email protected] != 1@[4626,10023,11822][65535,64764,40092] |
| 84 | +@ICMP [email protected] in { 3..5, 11 } || icmpv6.type in { 1..4 }@[4626,10023,11822][47031,63479,29812] |
| 85 | +@ARP@arp@[64250,61680,55255][4626,10023,11822] |
| 86 | +@ICMP@icmp || icmpv6@[64764,57568,65535][4626,10023,11822] |
| 87 | +@TCP [email protected] eq 1@[42148,0,0][65535,64764,40092] |
| 88 | +@SCTP [email protected]_type eq ABORT@[42148,0,0][65535,64764,40092] |
| 89 | +@IPv4 TTL low or unexpected@(ip.dst != 224.0.0.0/4 && ip.ttl < 5 && !(pim || ospf || eigrp || bgp || tcp.port==179)) || (ip.dst == 224.0.0.0/24 && ip.dst != 224.0.0.251 && ip.ttl != 1 && !(vrrp || carp || eigrp || rip || glbp))@[42148,0,0][60652,61680,60395] |
| 90 | +@IPv6 hop limit low or unexpected@(ipv6.dst != ff00::/8 && ipv6.hlim < 5 && !( ospf|| bgp || tcp.port==179)) || (ipv6.dst==ff00::/8 && ipv6.hlim not in {1, 64, 255})@[42148,0,0][60652,61680,60395] |
| 91 | +@Checksum [email protected]=="Bad" || ip.checksum.status=="Bad" || tcp.checksum.status=="Bad" || udp.checksum.status=="Bad" || sctp.checksum.status=="Bad" || mstp.checksum.status=="Bad" || cdp.checksum.status=="Bad" || edp.checksum.status=="Bad" || wlan.fcs.status=="Bad" || stt.checksum.status=="Bad"@[4626,10023,11822][63479,34695,34695] |
| 92 | +@SMB@smb || nbss || nbns || netbios@[65278,65535,53456][4626,10023,11822] |
| 93 | +@HTTP@http || tcp.port == 80 || http2@[58596,65535,51143][4626,10023,11822] |
| 94 | +@DCERPC@dcerpc@[51143,38807,65535][4626,10023,11822] |
| 95 | +@Routing@hsrp || eigrp || ospf || bgp || cdp || vrrp || carp || gvrp || igmp || ismp@[65535,62451,54998][4626,10023,11822] |
| 96 | +@TCP SYN/ [email protected] & 0x02 || tcp.flags.fin == 1@[41120,41120,41120][4626,10023,11822] |
| 97 | +@TCP@tcp@[59367,59110,65535][4626,10023,11822] |
| 98 | +@UDP@udp@[56026,61166,65535][4626,10023,11822] |
| 99 | +@Broadcast@eth[0] & 1@[65535,65535,65535][47802,48573,46774] |
| 100 | +@System Event@systemd_journal || sysdig@[59110,59110,59110][11565,28527,39578] |
0 commit comments