Skip to content

[CISCO Meraki] New CDFs#170

Open
james-vargas wants to merge 2 commits intomainfrom
jamesv-meraki-001
Open

[CISCO Meraki] New CDFs#170
james-vargas wants to merge 2 commits intomainfrom
jamesv-meraki-001

Conversation

@james-vargas
Copy link
Copy Markdown
Collaborator

Add 21 Sigma detection rules for Cisco Meraki under tm-v1-sigma-rules/third_party_logs/Cisco/Meraki. Rules cover 802.1X deauth/failed auth, blocked DHCP responses, VPN/IKE Phase 1/2 establish/teardown, IPsec/ISAKMP legacy events, IDS signature matches (ingress/egress/blocked), AMP dispositions (malicious/blocked/retrospective), L3 firewall rule matches, rogue SSID/SSID spoofing, spanning-tree guard state changes, VRRP virtual router collisions, wireless packet flood detection, and VPN connectivity changes. Each rule targets THIRD_PARTY_LOG Meraki events using vendorParsed string conditions and is tagged under the tm-v1 taxonomy to improve Meraki detection coverage.

Add 21 Sigma detection rules for Cisco Meraki under tm-v1-sigma-rules/third_party_logs/Cisco/Meraki. Rules cover 802.1X deauth/failed auth, blocked DHCP responses, VPN/IKE Phase 1/2 establish/teardown, IPsec/ISAKMP legacy events, IDS signature matches (ingress/egress/blocked), AMP dispositions (malicious/blocked/retrospective), L3 firewall rule matches, rogue SSID/SSID spoofing, spanning-tree guard state changes, VRRP virtual router collisions, wireless packet flood detection, and VPN connectivity changes. Each rule targets THIRD_PARTY_LOG Meraki events using vendorParsed string conditions and is tagged under the tm-v1 taxonomy to improve Meraki detection coverage.
Update Sigma rules for Cisco/Meraki third-party logs: change logsource.product from 'Meraki' to 'Cisco' and add a productName detection (pname: 'Meraki') to each rule, combining it with the existing string conditions. This groups the rules under the Cisco third-party product while ensuring they still match Meraki-specific vendorParsed fields.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants