Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .last_used_sid
Original file line number Diff line number Diff line change
@@ -1,2 +1,2 @@
Normal Rule: 5017960
Normal Rule: 5017985
Fingerprint: 5100196
1 change: 1 addition & 0 deletions dynamic.rules
Original file line number Diff line number Diff line change
Expand Up @@ -282,3 +282,4 @@ alert any any any -> any any (msg:"[DYNAMIC] Mimecast V2 Logs Detected"; program
alert any any any -> any any (msg:"[DYNAMIC] Sophos Firewall Logs Detected"; program:sophos; dynamic_load: $RULE_PATH/sophos_firewall.rules; classtype:dynamic-rules; sid:5017456; rev:1;)
alert any any any -> any any (msg:"[DYNAMIC] Zscaler ZIA Logs Detected"; program:Zscaler; dynamic_load: $RULE_PATH/zscaler-zia.rules; classtype:dynamic-rules; sid:5017934; rev:1;)
alert any any any -> any any (msg:"[DYNAMIC] Zscaler ZPA Logs Detected"; program:Zscaler; dynamic_load: $RULE_PATH/zscaler-zpa.rules; classtype:dynamic-rules; sid:5017935; rev:1;)
alert any any any -> any any (msg:"[DYNAMIC] MSAPI-MicrosoftTeams logs detected via program"; program:MicrosoftTeams; dynamic_load: $RULE_PATH/msapi-microsoftteams.rules; classtype:dynamic-rules; sid:5017961; rev:1;)
2 changes: 1 addition & 1 deletion fortinet-aetas.rules
Original file line number Diff line number Diff line change
Expand Up @@ -30,4 +30,4 @@ alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[FORTINET-AETAS] Administrat
alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[FORTINET-AETAS] Admin authentication access at suspicious time"; content: "38001 type="; content: "succeeded in authentication"; parse_src_ip: 1; alert_time: days $SAGAN_DAYS, hours $SAGAN_HOURS; classtype: successful-admin; sid: 5002045; rev:3;)
alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[FORTINET-AETAS] SSH traffic detected at suspicious time"; content: " service=SSH "; classtype: suspicious-traffic; parse_src_ip: 1; parse_dst_ip: 2; alert_time: days $SAGAN_DAYS, hours $SAGAN_HOURS; sid: 5002046; rev:4;)

alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[EXPERIMENTAL] [FORTIGATE] Suspicious - Unknown Application Activity Outside Business Hours"; content:"type=|22|traffic|22|"; content:"subtype=|22|forward|22|"; content:"app=|22|UNKNOWN|22|"; pcre:"/srcip=(10\.\d+\.\d+\.\d+|172\.(1[6-9]|2[0-9]|3[0-1])\.\d+\.\d+|192\.168\.\d+\.\d+)/"; parse_src_ip:1; alert_time:days 12345,hours 1800-0800; threshold:type suppress,track by_src,count 3,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:9870022; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[FORTIGATE] Suspicious - Unknown Application Activity Outside Business Hours"; content:"type=|22|traffic|22|"; content:"subtype=|22|forward|22|"; content:"app=|22|UNKNOWN|22|"; pcre:"/srcip=(10\.\d+\.\d+\.\d+|172\.(1[6-9]|2[0-9]|3[0-1])\.\d+\.\d+|192\.168\.\d+\.\d+)/"; parse_src_ip:1; alert_time:days 12345,hours 1800-0800; threshold:type suppress,track by_src,count 3,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:5017981; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
6 changes: 3 additions & 3 deletions fortinet.rules
Original file line number Diff line number Diff line change
Expand Up @@ -418,9 +418,9 @@ alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[FORTINET] VPN Brute Force f
alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[FORTINET] VPN Login After Brute Force for Same User"; content:"logid=|22|0101039424|22|"; content:"type="; content:"subtype="; parse_src_ip:2; normalize; flexbits:isset,username,brute_force; threshold:type suppress,track by_username, count 5, seconds 14400; reference:url,https://docs.fortinet.com/document/fortigate/7.6.2/fortios-log-message-reference/39424/39424-log-id-event-ssl-vpn-user-tunnel-up; content:"- - - -"; classtype:correlated-attack; sid:5017314; rev:3;)
#===========================================================

alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[EXPERIMENTAL] [FORTIGATE] Suspicious - Unknown Application on Standard Web Port"; content:"type=|22|traffic|22|"; content:"subtype=|22|forward|22|"; content:"app=|22|UNKNOWN|22|"; pcre:"/dstport=(80|443)[^\d]/"; pcre:"/srcip=(10\.\d+\.\d+\.\d+|172\.(1[6-9]|2[0-9]|3[0-1])\.\d+\.\d+|192\.168\.\d+\.\d+)/"; parse_src_ip:1; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:9870019; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[FORTIGATE] Suspicious - Unknown Application on Standard Web Port"; content:"type=|22|traffic|22|"; content:"subtype=|22|forward|22|"; content:"app=|22|UNKNOWN|22|"; pcre:"/dstport=(80|443)[^\d]/"; pcre:"/srcip=(10\.\d+\.\d+\.\d+|172\.(1[6-9]|2[0-9]|3[0-1])\.\d+\.\d+|192\.168\.\d+\.\d+)/"; parse_src_ip:1; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:5017978; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)

alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[EXPERIMENTAL] [FORTIGATE] Suspicious - Unknown Application on High Destination Port"; content:"type=|22|traffic|22|"; content:"subtype=|22|forward|22|"; content:"app=|22|UNKNOWN|22|"; pcre:"/dstport=(1[0-9]{4,}|[2-9]\d{4,})[^\d]/"; pcre:"/srcip=(10\.\d+\.\d+\.\d+|172\.(1[6-9]|2[0-9]|3[0-1])\.\d+\.\d+|192\.168\.\d+\.\d+)/"; parse_src_ip:1; after:track by_src,count 3,seconds 600; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:9870020; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[FORTIGATE] Suspicious - Unknown Application on High Destination Port"; content:"type=|22|traffic|22|"; content:"subtype=|22|forward|22|"; content:"app=|22|UNKNOWN|22|"; pcre:"/dstport=(1[0-9]{4,}|[2-9]\d{4,})[^\d]/"; pcre:"/srcip=(10\.\d+\.\d+\.\d+|172\.(1[6-9]|2[0-9]|3[0-1])\.\d+\.\d+|192\.168\.\d+\.\d+)/"; parse_src_ip:1; after:track by_src,count 3,seconds 600; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:5017979; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)

alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[EXPERIMENTAL] [FORTIGATE] Suspicious - Large Outbound Data Transfer with Unknown Application"; content:"type=|22|traffic|22|"; content:"subtype=|22|forward|22|"; content:"app=|22|UNKNOWN|22|"; pcre:"/sentbyte=([5-9]\d{6}|\d{7,})[^\d]/"; pcre:"/srcip=(10\.\d+\.\d+\.\d+|172\.(1[6-9]|2[0-9]|3[0-1])\.\d+\.\d+|192\.168\.\d+\.\d+)/"; parse_src_ip:1; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:9870021; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[FORTIGATE] Suspicious - Large Outbound Data Transfer with Unknown Application"; content:"type=|22|traffic|22|"; content:"subtype=|22|forward|22|"; content:"app=|22|UNKNOWN|22|"; pcre:"/sentbyte=([5-9]\d{6}|\d{7,})[^\d]/"; pcre:"/srcip=(10\.\d+\.\d+\.\d+|172\.(1[6-9]|2[0-9]|3[0-1])\.\d+\.\d+|192\.168\.\d+\.\d+)/"; parse_src_ip:1; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:5017980; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[FORTIGATE] ArcheClient C2 - Unidentified TCP Beaconing on Port 9000"; content:"type=|22|traffic|22|"; content:"subtype=|22|forward|22|"; content:"proto=6"; content:"dstport=9000"; content:"sentbyte=52"; content:"rcvdbyte=0"; content:"sentpkt=1"; content:"rcvdpkt=0"; pcre:"/srcip=(10\.\d+\.\d+\.\d+|172\.(1[6-9]|2[0-9]|3[0-1])\.\d+\.\d+|192\.168\.\d+\.\d+)/"; parse_src_ip:1; after:track by_src,count 5,seconds 3600; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:5017931; rev:2; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
2 changes: 1 addition & 1 deletion juniper-aetas.rules
Original file line number Diff line number Diff line change
Expand Up @@ -29,4 +29,4 @@
alert any $HOME_NET any -> $EXTERNAL_NET any (msg: "[JUNIPER-AETAS] VPN Login at suspicious time"; program: Juniper; pcre: "/Authentication successful|Login succeeded/i"; alert_time: days $SAGAN_DAYS, hours $SAGAN_HOURS; default_proto: tcp; default_dst_port: $HTTPS_PORT; classtype: successful-user; parse_src_ip: 1; sid:5002047; rev:3;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg: "[JUNIPER-AETAS] VPN Logout at suspicious time"; program: Juniper; content: "Logout from"; alert_time: days $SAGAN_DAYS, hours $SAGAN_HOURS; default_proto: tcp; default_dst_port: $HTTPS_PORT; classtype: successful-user; parse_src_ip: 1; sid:5002048; rev:3;)

alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[EXPERIMENTAL] [JUNIPER] Suspicious - Unknown Application Activity Outside Business Hours"; content:"APPTRACK_SESSION_CREATE"; content:"application=|22|UNKNOWN|22|"; content:"destination-zone-name=|22|untrust|22|"; content:"source-zone-name=|22|trust|22|"; parse_src_ip:1; alert_time:days 12345,hours 1800-0800; threshold:type suppress,track by_src,count 3,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:9870018; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[JUNIPER] Suspicious - Unknown Application Activity Outside Business Hours"; content:"APPTRACK_SESSION_CREATE"; content:"application=|22|UNKNOWN|22|"; content:"destination-zone-name=|22|untrust|22|"; content:"source-zone-name=|22|trust|22|"; parse_src_ip:1; alert_time:days 12345,hours 1800-0800; threshold:type suppress,track by_src,count 3,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:5017985; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
6 changes: 3 additions & 3 deletions juniper.rules
Original file line number Diff line number Diff line change
Expand Up @@ -109,9 +109,9 @@ alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[JUNIPER] VPN - Policy viola
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[ScreenOS] Juniper ScreenOS Login for Suspicious Admin user - system"; content: "Admin user system has logged on via"; nocase; content: "00515"; parse_src_ip: 1; reference:cve,2015-7755; reference:url,kb.juniper.net/InfoCenter/index?page=content&id=JSA10713&actp=search; default_proto: tcp; default_dst_port: $SSH_PORT; classtype:successful-admin; sid: 5002771; rev:4;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[ScreenOS] Juniper ScreenOS Login for Suspicious Admin user - username"; content:"Admin user"; content:"username"; content:"has logged on via"; content: "00515"; parse_src_ip: 1; reference:cve,2015-7755; reference:url,kb.juniper.net/InfoCenter/index?page=content&id=JSA10713&actp=search; default_proto: tcp; default_dst_port: $SSH_PORT; classtype:successful-admin; sid: 5002772; rev:4;)

#alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[EXPERIMENTAL] [JUNIPER] Suspicious - Unknown Application on Standard Web Port"; content:"APPTRACK_SESSION_CREATE"; content:"application=|22|UNKNOWN|22|"; content:"destination-zone-name=|22|untrust|22|"; content:"source-zone-name=|22|trust|22|"; meta_content:"destination-port=|22|%sagan%|22|",80,443; content:!"destination-port=|22|443|22| service-name=|22|junos-https|22|"; content:!"destination-port=|22|80|22| service-name=|22|junos-http|22|"; parse_src_ip:1; parse_dst_ip:2; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:9870015; rev:2; metadata:created_on 2026_06_17, updated_on 2026_06_30, mitreTactic TA0011, mitreTechnique T1071.001;)
#alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[JUNIPER] Suspicious - Unknown Application on Standard Web Port"; content:"APPTRACK_SESSION_CREATE"; content:"application=|22|UNKNOWN|22|"; content:"destination-zone-name=|22|untrust|22|"; content:"source-zone-name=|22|trust|22|"; meta_content:"destination-port=|22|%sagan%|22|",80,443; content:!"destination-port=|22|443|22| service-name=|22|junos-https|22|"; content:!"destination-port=|22|80|22| service-name=|22|junos-http|22|"; parse_src_ip:1; parse_dst_ip:2; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:5017982; rev:2; metadata:created_on 2026_06_17, updated_on 2026_06_30, mitreTactic TA0011, mitreTechnique T1071.001;)

alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[EXPERIMENTAL] [JUNIPER] Suspicious - Unknown Application on High Destination Port"; content:"APPTRACK_SESSION_CREATE"; content:"application=|22|UNKNOWN|22|"; content:"destination-zone-name=|22|untrust|22|"; content:"source-zone-name=|22|trust|22|"; pcre:"/destination-port=(1[0-9]{4,}|[2-9]\d{4,})/"; parse_src_ip:1; after:track by_src,count 3,seconds 600; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:9870016; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[JUNIPER] Suspicious - Unknown Application on High Destination Port"; content:"APPTRACK_SESSION_CREATE"; content:"application=|22|UNKNOWN|22|"; content:"destination-zone-name=|22|untrust|22|"; content:"source-zone-name=|22|trust|22|"; pcre:"/destination-port=(1[0-9]{4,}|[2-9]\d{4,})/"; parse_src_ip:1; after:track by_src,count 3,seconds 600; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:5017983; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)

alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[EXPERIMENTAL] [JUNIPER] Suspicious - Large Outbound Data Transfer with Unknown Application"; content:"APPTRACK_SESSION_VOL_UPDATE"; content:"application=|22|UNKNOWN|22|"; content:"destination-zone-name=|22|untrust|22|"; content:"source-zone-name=|22|trust|22|"; pcre:"/bytes-from-client=([5-9]\d{6}|\d{7,})/"; parse_src_ip:1; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:9870017; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[JUNIPER] Suspicious - Large Outbound Data Transfer with Unknown Application"; content:"APPTRACK_SESSION_VOL_UPDATE"; content:"application=|22|UNKNOWN|22|"; content:"destination-zone-name=|22|untrust|22|"; content:"source-zone-name=|22|trust|22|"; pcre:"/bytes-from-client=([5-9]\d{6}|\d{7,})/"; parse_src_ip:1; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:5017984; rev:1; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
alert any $HOME_NET any -> $EXTERNAL_NET any (msg:"[JUNIPER] ArcheClient C2 - Unidentified TCP Beaconing on Port 9000"; content:"APPTRACK_SESSION_VOL_UPDATE"; content:"destination-port=|22|9000|22|"; content:"source-zone-name=|22|trust|22|"; content:"destination-zone-name=|22|untrust|22|"; content:"application=|22|UNKNOWN|22|"; content:"bytes-from-client=|22|52|22|"; content:"bytes-from-server=|22|0|22|"; content:"packets-from-client=|22|1|22|"; content:"packets-from-server=|22|0|22|"; parse_src_ip:1; after:track by_src,count 5,seconds 3600; threshold:type suppress,track by_src,count 1,seconds 3600; classtype:trojan-activity; reference:url,attack.mitre.org/techniques/T1071/001; sid:5017930; rev:3; metadata:created_on 2026_06_17, updated_on 2026_06_17, mitreTactic TA0011, mitreTechnique T1071.001;)
Loading
Loading