<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom signature for catch specific query in Custom Signatures</title>
    <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-catch-specific-query/m-p/452166#M412</link>
    <description>&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to catch suspicious ldap queries (recon activity).&lt;BR /&gt;For the example I want catch this kind of querie : (primaryGroupID=512)&lt;/P&gt;&lt;P&gt;I tried to make a custom rule. However for ldap, there are only 2 possibilities:&lt;BR /&gt;- ldap-req-searchrequest-baseobject&lt;BR /&gt;- ldap-rsp-searchresentry-objectname&lt;BR /&gt;both of them don't fit my needs cause they don't match the filter field.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I tried with unknown-req-tcp-payload but it did not work. Reading the forum I understood that I can't use this context since ldap is seen as a known application.&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/custom-signatures/custom-threat-signature-search-full-tcp-payload-of-any-appid/td-p/349450" target="_blank"&gt;https://live.paloaltonetworks.com/t5/custom-signatures/custom-threat-signature-search-full-tcp-payload-of-any-appid/td-p/349450&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;So I'm running out of ideas to catch this kind of request.&lt;/P&gt;&lt;P&gt;If somebody have a tips&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank's&lt;/P&gt;</description>
    <pubDate>Wed, 08 Dec 2021 18:45:51 GMT</pubDate>
    <dc:creator>jsv93</dc:creator>
    <dc:date>2021-12-08T18:45:51Z</dc:date>
    <item>
      <title>Custom signature for catch specific query</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-catch-specific-query/m-p/452166#M412</link>
      <description>&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to catch suspicious ldap queries (recon activity).&lt;BR /&gt;For the example I want catch this kind of querie : (primaryGroupID=512)&lt;/P&gt;&lt;P&gt;I tried to make a custom rule. However for ldap, there are only 2 possibilities:&lt;BR /&gt;- ldap-req-searchrequest-baseobject&lt;BR /&gt;- ldap-rsp-searchresentry-objectname&lt;BR /&gt;both of them don't fit my needs cause they don't match the filter field.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I tried with unknown-req-tcp-payload but it did not work. Reading the forum I understood that I can't use this context since ldap is seen as a known application.&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/custom-signatures/custom-threat-signature-search-full-tcp-payload-of-any-appid/td-p/349450" target="_blank"&gt;https://live.paloaltonetworks.com/t5/custom-signatures/custom-threat-signature-search-full-tcp-payload-of-any-appid/td-p/349450&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;So I'm running out of ideas to catch this kind of request.&lt;/P&gt;&lt;P&gt;If somebody have a tips&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank's&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 18:45:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-catch-specific-query/m-p/452166#M412</guid>
      <dc:creator>jsv93</dc:creator>
      <dc:date>2021-12-08T18:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Custom signature for catch specific query</title>
      <link>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-catch-specific-query/m-p/458525#M416</link>
      <description>&lt;P&gt;Please see if this helps as this is new feature in 10.0 with the enhanced signature match:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/custom-signatures/custom-threat-signature-search-full-tcp-payload-of-any-appid/td-p/349450" target="_blank" rel="noopener"&gt;Solved: LIVEcommunity - Custom threat signature- search full TCP payload of any AppId - LIVEcommunity - 349450 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/content-inspection-features/enhanced-pattern-matching-engine.html#iddc51c078-bc5c-4c95-bba4-dd5763f2b549" target="_blank" rel="noopener"&gt;Enhanced Pattern-Matching Engine (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jan 2022 09:00:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/custom-signatures/custom-signature-for-catch-specific-query/m-p/458525#M416</guid>
      <dc:creator>nikoolayy1</dc:creator>
      <dc:date>2022-01-13T09:00:31Z</dc:date>
    </item>
  </channel>
</rss>

