<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom Snort Signature context operator not found in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-snort-signature-context-operator-not-found/m-p/354727#M364</link>
    <description>&lt;P&gt;creating a custom snort signature on Palo alto Firewall but didn’t found the concern context operator for match pattern.&lt;/P&gt;&lt;P&gt;Shall we create a context operator or how it can add the pattern if the context operator is not available?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET 443 (msg:"[CIS] Emotet C2 Traffic Using Form Data to Send Passwords"; content:"POST"; &lt;FONT color="#FF0000"&gt;http_method&lt;/FONT&gt;; content:"&lt;FONT color="#333399"&gt;Content-Type|3a 20|multipart/form-data|3b 20|boundary=&lt;/FONT&gt;"; http_header; fast_pattern; content:"Content-Disposition|3a 20|form-data|3b 20|name=|22|"; http_client_body; content:!"------WebKitFormBoundary"; &lt;FONT color="#FF0000"&gt;http_client_body&lt;/FONT&gt;; &lt;FONT color="#333399"&gt;content:!"Cookie|3a|"; pcre:"/:?(chrome|firefox|safari|opera|ie|edge) passwords/i&lt;/FONT&gt;"; reference:url,cofense.com/flash-bulletin-emotet-epoch-1-changes-c2-communication/; sid:1; rev:2;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not available&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;http_method&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;http_client_body&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snort.jpg" style="width: 498px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28123i31F3B68F04518D9C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Snort.jpg" alt="Snort.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Oct 2020 07:16:15 GMT</pubDate>
    <dc:creator>Mohammed_Yasin</dc:creator>
    <dc:date>2020-10-07T07:16:15Z</dc:date>
    <item>
      <title>Custom Snort Signature context operator not found</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-snort-signature-context-operator-not-found/m-p/354727#M364</link>
      <description>&lt;P&gt;creating a custom snort signature on Palo alto Firewall but didn’t found the concern context operator for match pattern.&lt;/P&gt;&lt;P&gt;Shall we create a context operator or how it can add the pattern if the context operator is not available?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET 443 (msg:"[CIS] Emotet C2 Traffic Using Form Data to Send Passwords"; content:"POST"; &lt;FONT color="#FF0000"&gt;http_method&lt;/FONT&gt;; content:"&lt;FONT color="#333399"&gt;Content-Type|3a 20|multipart/form-data|3b 20|boundary=&lt;/FONT&gt;"; http_header; fast_pattern; content:"Content-Disposition|3a 20|form-data|3b 20|name=|22|"; http_client_body; content:!"------WebKitFormBoundary"; &lt;FONT color="#FF0000"&gt;http_client_body&lt;/FONT&gt;; &lt;FONT color="#333399"&gt;content:!"Cookie|3a|"; pcre:"/:?(chrome|firefox|safari|opera|ie|edge) passwords/i&lt;/FONT&gt;"; reference:url,cofense.com/flash-bulletin-emotet-epoch-1-changes-c2-communication/; sid:1; rev:2;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not available&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;http_method&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;http_client_body&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snort.jpg" style="width: 498px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28123i31F3B68F04518D9C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Snort.jpg" alt="Snort.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 07:16:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-snort-signature-context-operator-not-found/m-p/354727#M364</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-10-07T07:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Snort Signature context operator not found</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-snort-signature-context-operator-not-found/m-p/386593#M378</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110" target="_blank"&gt;@Mohammed_Yasin&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;http_method in the Custom Vulnerability Object is the&amp;nbsp;http-method&amp;nbsp;Qualifier and the&amp;nbsp;http_client_body is the&amp;nbsp;http-req-message-body&amp;nbsp;Context, i.e.,:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CCACieszkowski_0-1613655319790.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29988i15960FA64207445A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CCACieszkowski_0-1613655319790.png" alt="CCACieszkowski_0-1613655319790.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Albert&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 13:35:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-snort-signature-context-operator-not-found/m-p/386593#M378</guid>
      <dc:creator>CCACieszkowski</dc:creator>
      <dc:date>2021-02-18T13:35:31Z</dc:date>
    </item>
  </channel>
</rss>

