Skip to content

Commit

Permalink
suricata.rules: 'PATH DEV' -> 'DEV PATH'
Browse files Browse the repository at this point in the history
  • Loading branch information
aiooss-anssi committed Jan 16, 2024
1 parent cb60365 commit 5f5cacc
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion suricata/rules/suricata.rules
Original file line number Diff line number Diff line change
Expand Up @@ -92,7 +92,7 @@ alert ip any any -> $HOME_NET any (msg: "Found LDAP 'givenName='"; flow:to_serve
alert ip any any -> $HOME_NET any (msg: "Found LDAP 'objectClass='"; flow:to_server; content: "objectClass|3d|"; metadata: tag LDAP FIELD, color warning; sid: 4103;)
alert ip any any -> $HOME_NET any (msg: "Found LDAP 'userPassword='"; flow:to_server; content: "userPassword|3d|"; metadata: tag LDAP FIELD, color warning; sid: 4104;)
alert ip any any -> $HOME_NET any (msg: "Found NodeJS serialized function '_$$ND_FUNC$$_'"; flow:to_server; content: "|5f 24 24|ND_FUNC|24 24 5f|"; nocase; metadata: tag NODEJS NDFUNC, color warning; sid: 4151;)
alert ip any any -> $HOME_NET any (msg: "Found path '/dev/'"; flow:to_server; content: "/dev/"; metadata: tag PATH DEV, color warning; sid: 4201;)
alert ip any any -> $HOME_NET any (msg: "Found path '/dev/'"; flow:to_server; content: "/dev/"; metadata: tag DEV PATH, color warning; sid: 4201;)
alert ip any any -> $HOME_NET any (msg: "Found path '/etc/'"; flow:to_server; content: "/etc/"; metadata: tag ETC PATH, color warning; sid: 4202;)
alert ip any any -> $HOME_NET any (msg: "Found path '/proc/'"; flow:to_server; content: "/proc/"; metadata: tag PROC PATH, color warning; sid: 4203;)
alert ip any any -> $HOME_NET any (msg: "Found path '/var/lib/'"; flow:to_server; content: "/var/lib/"; metadata: tag VARLIB PATH, color warning; sid: 4204;)
Expand Down

0 comments on commit 5f5cacc

Please sign in to comment.