Skip to content

Commit 554cae3

Browse files
committed
Updated Wireshark configuration.
1 parent d904527 commit 554cae3

File tree

3 files changed

+52
-35
lines changed

3 files changed

+52
-35
lines changed

src/wireshark/colorfilters

Lines changed: 21 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -77,22 +77,24 @@
7777
@[email protected]_type == 7 || sctp.chunk_type == 8 || sctp.chunk_type == 14@[65535,65535,14392][0,0,0]
7878
@[email protected]_type == 4 || sctp.chunk_type == 5@[52428,52428,65535][0,0,0]
7979
@[email protected]_type == 3@[59367,58339,59367][0,0,0]
80-
@Bad [email protected]@[0,0,0][65535,24415,24415]
81-
@HSRP State [email protected] != 8 && hsrp.state != 16@[0,0,0][65535,63222,0]
82-
@Spanning Tree Topology [email protected] == 0x80@[0,0,0][65535,63222,0]
83-
@OSPF State [email protected] != 1@[0,0,0][65535,63222,0]
84-
@ICMP [email protected] eq 3 || icmp.type eq 4 || icmp.type eq 11@[0,0,0][0,65535,3598]
85-
@ARP@arp@[54998,59624,65535][0,0,0]
86-
@ICMP@icmp@[49858,49858,65535][0,0,0]
87-
@TCP [email protected] eq 1@[37008,0,0][65535,63222,32896]
88-
@Low [email protected] < 5@[37008,0,0][65535,65535,65535]
89-
@Checksum [email protected]_bad==1 || ip.checksum_bad==1 || tcp.checksum_bad || udp.checksum_bad@[0,0,0][65535,24415,24415]
90-
@SMB@smb || nbss || nbns || nbipx || ipxsap || netbios@[65535,64250,39321][0,0,0]
91-
@HTTP@http || tcp.port == 80@[36237,65535,32639][0,0,0]
92-
@IPX@ipx || stp@[65535,58339,58853][0,0,0]
93-
@DCERPC@dcerpc@[51143,38807,65535][0,0,0]
94-
@Routing@hsrp || eigrp || ospf || bgp || cdp || vrrp || gvrp || igmp || ismp@[65535,62451,54998][0,0,0]
95-
@TCP SYN/[email protected] & 0x02 || tcp.flags.fin == 1@[41120,41120,41120][0,0,0]
96-
@TCP@tcp@[59367,59110,65535][0,0,0]
97-
@UDP@udp@[28784,57568,65535][0,0,0]
98-
@Broadcast@eth[0] & 1@[65535,65535,65535][32896,32896,32896]
80+
@Bad [email protected] && !tcp.analysis.window_update && !tcp.analysis.keep_alive && !tcp.analysis.keep_alive_ack@[4626,10023,11822][63479,34695,34695]
81+
@HSRP State [email protected] != 8 && hsrp.state != 16@[4626,10023,11822][65535,64764,40092]
82+
@Spanning Tree Topology [email protected] == 0x80@[4626,10023,11822][65535,64764,40092]
83+
@OSPF State [email protected] != 1@[4626,10023,11822][65535,64764,40092]
84+
@ICMP [email protected] in { 3..5, 11 } || icmpv6.type in { 1..4 }@[4626,10023,11822][47031,63479,29812]
85+
@ARP@arp@[64250,61680,55255][4626,10023,11822]
86+
@ICMP@icmp || icmpv6@[64764,57568,65535][4626,10023,11822]
87+
@TCP [email protected] eq 1@[42148,0,0][65535,64764,40092]
88+
@SCTP [email protected]_type eq ABORT@[42148,0,0][65535,64764,40092]
89+
@IPv4 TTL low or unexpected@(ip.dst != 224.0.0.0/4 && ip.ttl < 5 && !(pim || ospf || eigrp || bgp || tcp.port==179)) || (ip.dst == 224.0.0.0/24 && ip.dst != 224.0.0.251 && ip.ttl != 1 && !(vrrp || carp || eigrp || rip || glbp))@[42148,0,0][60652,61680,60395]
90+
@IPv6 hop limit low or unexpected@(ipv6.dst != ff00::/8 && ipv6.hlim < 5 && !( ospf|| bgp || tcp.port==179)) || (ipv6.dst==ff00::/8 && ipv6.hlim not in {1, 64, 255})@[42148,0,0][60652,61680,60395]
91+
@Checksum [email protected]=="Bad" || ip.checksum.status=="Bad" || tcp.checksum.status=="Bad" || udp.checksum.status=="Bad" || sctp.checksum.status=="Bad" || mstp.checksum.status=="Bad" || cdp.checksum.status=="Bad" || edp.checksum.status=="Bad" || wlan.fcs.status=="Bad" || stt.checksum.status=="Bad"@[4626,10023,11822][63479,34695,34695]
92+
@SMB@smb || nbss || nbns || netbios@[65278,65535,53456][4626,10023,11822]
93+
@HTTP@http || tcp.port == 80 || http2@[58596,65535,51143][4626,10023,11822]
94+
@DCERPC@dcerpc@[51143,38807,65535][4626,10023,11822]
95+
@Routing@hsrp || eigrp || ospf || bgp || cdp || vrrp || carp || gvrp || igmp || ismp@[65535,62451,54998][4626,10023,11822]
96+
@TCP SYN/[email protected] & 0x02 || tcp.flags.fin == 1@[41120,41120,41120][4626,10023,11822]
97+
@TCP@tcp@[59367,59110,65535][4626,10023,11822]
98+
@UDP@udp@[56026,61166,65535][4626,10023,11822]
99+
@Broadcast@eth[0] & 1@[65535,65535,65535][47802,48573,46774]
100+
@System Event@systemd_journal || sysdig@[59110,59110,59110][11565,28527,39578]

src/wireshark/decode_as_entries

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
# "Decode As" entries file for Wireshark 4.7.0.
2+
#
3+
# This file is regenerated each time "Decode As" preferences
4+
# are saved within Wireshark. Making manual changes should be safe,
5+
# however.
6+
decode_as_entry: tcp.port,8999,(none),NetPerfMeter
7+
decode_as_entry: tcp.port,9000,S101,NetPerfMeter
8+
decode_as_entry: tcp.port,9001,(none),NetPerfMeter
9+
decode_as_entry: udp.port,9000,(none),NetPerfMeter

src/wireshark/dfilters

Lines changed: 22 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,22 @@
1-
"Ethernet address 00:00:5e:00:53:00" eth.addr == 00:00:5e:00:53:00
2-
"Ethernet type 0x0806 (ARP)" eth.type == 0x0806
3-
"Ethernet broadcast" eth.addr == ff:ff:ff:ff:ff:ff
4-
"No ARP" not arp
5-
"IPv4 only" ip
6-
"IPv4 address 192.0.2.1" ip.addr == 192.0.2.1
7-
"IPv4 address isn't 192.0.2.1 (don't use != for this!)" !(ip.addr == 192.0.2.1)
8-
"IPv6 only" ipv6
9-
"IPv6 address 2001:db8::1" ipv6.addr == 2001:db8::1
10-
"TCP only" tcp
11-
"UDP only" udp
12-
"Non-DNS" !(udp.port == 53 || tcp.port == 53)
13-
"TCP or UDP port is 80 (HTTP)" tcp.port == 80 || udp.port == 80
14-
"HTTP" http
15-
"No ARP and no DNS" not arp and !(udp.port == 53)
16-
"Non-HTTP and non-SMTP to/from 192.0.2.1" ip.addr == 192.0.2.1 and not tcp.port in {80 25}
1+
"NetPerfMeter Control Traffic" netperfmeter && (netperfmeter.message_type != 0x04) && (netperfmeter.message_type != 0x05)
2+
"NetPerfMeter Data Traffic" (netperfmeter.message_type == 0x04) || (netperfmeter.message_type == 0x05)
3+
"HiPerConTracer Traffic" hipercontracer
4+
"RSerPool Traffic" asap||enrp
5+
"RSerPool Traffic via SCTP + SCTP Control, without Monitoring" (sctp&&enrp&&(!((enrp.message_type==0x01)&&(!enrp.message_flags&0x01))))||(sctp&&(asap&&(((asap.message_type!=0x07)&&(asap.message_type!=0x08)&&(asap.message_type!=0x0b))||((asap.message_type==0x07)&&(asap.message_flags&0x01)))))||((!(asap||enrp))&&(sctp.chunk_type != 3)&&(sctp.chunk_type != 4)&&(sctp.chunk_type != 5))
6+
"RSerPool Traffic via SCTP, without Monitoring" (sctp&&enrp&&(!((enrp.message_type==0x01)&&(!enrp.message_flags&0x01))))||(sctp&&(asap&&(((asap.message_type!=0x07)&&(asap.message_type!=0x08)&&(asap.message_type!=0x0b))||((asap.message_type==0x07)&&(asap.message_flags&0x01)))))
7+
"RSerPool Traffic via SCTP" sctp&&(asap||enrp)
8+
"RSerPool Control Channel Traffic" (asap.message_type == 0x0b) || (asap.message_type == 0x0c) || (asap.message_type == 0x0d)
9+
"RSerPool Pool Element Traffic" (asap.message_type == 0x01) || (asap.message_type == 0x02) || (asap.message_type == 0x03) || (asap.message_type == 0x04)
10+
"RSerPool Pool User Traffic" (asap.message_type == 0x05) || (asap.message_type == 0x06) || (asap.message_type == 0x09)
11+
"RSerPool ASAP Traffic via SCTP, without Monitoring" sctp&&(asap&&(((asap.message_type!=0x07)&&(asap.message_type!=0x08)&&(asap.message_type!=0x0b))||((asap.message_type==0x07)&&(asap.message_flags&0x01))))
12+
"RSerPool ASAP Traffic via SCTP" sctp&&asap
13+
"RSerPool ENRP Traffic via SCTP, without Monitoring" sctp&&enrp&&(!((enrp.message_type==0x01)&&(!enrp.message_flags&0x01)))
14+
"RSerPool ENRP Traffic via SCTP" sctp&&enrp
15+
"RSerPool Home-Registrar Changes" sctp&&(asap&&(asap.message_type==0x07)&&(asap.message_flags&0x01))
16+
"RSerPool Registrar Takeovers" sctp&&((enrp&&((enrp.message_type==0x07)||(enrp.message_type==0x08)||(enrp.message_type==0x09))) || (asap&&(asap.message_type==0x07)&&(asap.message_flags&0x01)))
17+
"RSerPool Registrar Synchronizations" sctp&&enrp&&((enrp.message_type==0x02)||(enrp.message_type==0x03)||(enrp.message_type==0x05)||(enrp.message_type==0x06))
18+
"RSerPool Registrar Failure Handling" sctp&&((enrp&&((enrp.message_type==0x07)||(enrp.message_type==0x08)||(enrp.message_type==0x09)||(enrp.message_type==0x02)||(enrp.message_type==0x03))) || (asap&&(asap.message_type==0x07)&&(asap.message_flags&0x01)))
19+
"RSerPool Application CalcAppProtocol" calcappprotocol || (asap.message_type == 0x0b) || (asap.message_type == 0x0c)
20+
"RSerPool Application FractalGeneratorProtocol" fractalgeneratorprotocol || (asap.message_type == 0x0b) || (asap.message_type == 0x0c)
21+
"RSerPool Application PingPongProtocol" pingpongprotocol || (asap.message_type == 0x0b) || (asap.message_type == 0x0c)
22+
"RSerPool Application ScriptingServiceProtocol" ssp || (asap.message_type == 0x0b) || (asap.message_type == 0x0c)

0 commit comments

Comments
 (0)