<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: custom snort signature add the pattern if the context operator is not found in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/custom-snort-signature-add-the-pattern-if-the-context-operator/m-p/386589#M1076</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;http_method in the Custom Vulnerability Object is the&amp;nbsp;http-method&amp;nbsp;Qualifier and the&amp;nbsp;http_client_body is the&amp;nbsp;http-req-message-body&amp;nbsp;Context, i.e.,:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CCACieszkowski_0-1613654715614.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29986i6339FFA5491F1095/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CCACieszkowski_0-1613654715614.png" alt="CCACieszkowski_0-1613654715614.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Albert&lt;/P&gt;</description>
    <pubDate>Thu, 18 Feb 2021 13:25:53 GMT</pubDate>
    <dc:creator>CCACieszkowski</dc:creator>
    <dc:date>2021-02-18T13:25:53Z</dc:date>
    <item>
      <title>custom snort signature add the pattern if the context operator is not found</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/custom-snort-signature-add-the-pattern-if-the-context-operator/m-p/354737#M962</link>
      <description>&lt;P&gt;creating a custom snort signature on Palo alto Firewall but didn’t found the concern context operator for match pattern.&lt;/P&gt;&lt;P&gt;Shall we create a context operator or how it can add the pattern if the context operator is not available?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET 443 (msg:"[CIS] Emotet C2 Traffic Using Form Data to Send Passwords"; content:"POST";&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;http_method&lt;/FONT&gt;; content:"&lt;FONT color="#333399"&gt;Content-Type|3a 20|multipart/form-data|3b 20|boundary=&lt;/FONT&gt;"; http_header; fast_pattern; content:"Content-Disposition|3a 20|form-data|3b 20|name=|22|"; http_client_body; content:!"------WebKitFormBoundary";&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;http_client_body&lt;/FONT&gt;;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#333399"&gt;content:!"Cookie|3a|"; pcre:"/:?(chrome|firefox|safari|opera|ie|edge) passwords/i&lt;/FONT&gt;"; reference:url,cofense.com/flash-bulletin-emotet-epoch-1-changes-c2-communication/; sid:1; rev:2;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not available&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;http_method&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;http_client_body&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snort.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28124i30D6D4D2680C3C38/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Snort.jpg" alt="Snort.jpg" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 07:17:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/custom-snort-signature-add-the-pattern-if-the-context-operator/m-p/354737#M962</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-10-07T07:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: custom snort signature add the pattern if the context operator is not f</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/custom-snort-signature-add-the-pattern-if-the-context-operator/m-p/354986#M963</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Writing custom signatures is something I always leave to the vendors, its their job :). If you setup your PAN with the everything turned on, anti-virus, spyware, url filtering, dns sinkhole, using secure dns (even if it snot PAN's), SSL Decrypt, wildfire, tight policies, I think you will find not much if anything can get through. Also enable the telemetry to be sent to PAN, it helps hem write signatures for everyone :), a small way to give back.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also use best practices on the rest of the network as well as endpoints (AV etc).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can always use their threat db to search and see if they already have something. If they dont put in a TAC request and they'll work on one.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 21:42:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/custom-snort-signature-add-the-pattern-if-the-context-operator/m-p/354986#M963</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-10-07T21:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: custom snort signature add the pattern if the context operator is not f</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/custom-snort-signature-add-the-pattern-if-the-context-operator/m-p/358020#M969</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hello,&amp;nbsp;&lt;A href="https://8ball-pool.io" target="_self"&gt;&lt;FONT size="1 2 3 4 5 6 7" color="#FFFFFF"&gt;8 ball pool&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Writing custom signatures is something I always leave to the vendors, its their job :). If you setup your PAN with the everything turned on, anti-virus, spyware, url filtering, dns sinkhole, using secure dns (even if it snot PAN's), SSL Decrypt, wildfire, tight policies, I think you will find not much if anything can get through. Also enable the telemetry to be sent to PAN, it helps hem write signatures for everyone :), a small way to give back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also use best practices on the rest of the network as well as endpoints (AV etc).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can always use their threat db to search and see if they already have something. If they dont put in a TAC request and they'll work on one.&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank" rel="noopener"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thank you very much!! Very useful advice&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 08:25:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/custom-snort-signature-add-the-pattern-if-the-context-operator/m-p/358020#M969</guid>
      <dc:creator>leonblum</dc:creator>
      <dc:date>2020-10-26T08:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: custom snort signature add the pattern if the context operator is not found</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/custom-snort-signature-add-the-pattern-if-the-context-operator/m-p/386589#M1076</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;http_method in the Custom Vulnerability Object is the&amp;nbsp;http-method&amp;nbsp;Qualifier and the&amp;nbsp;http_client_body is the&amp;nbsp;http-req-message-body&amp;nbsp;Context, i.e.,:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CCACieszkowski_0-1613654715614.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29986i6339FFA5491F1095/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CCACieszkowski_0-1613654715614.png" alt="CCACieszkowski_0-1613654715614.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Albert&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 13:25:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/custom-snort-signature-add-the-pattern-if-the-context-operator/m-p/386589#M1076</guid>
      <dc:creator>CCACieszkowski</dc:creator>
      <dc:date>2021-02-18T13:25:53Z</dc:date>
    </item>
  </channel>
</rss>

