<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Translate Suricata IPS signatures into custom Palo Alto Networks threat signatures in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/translate-suricata-ips-signatures-into-custom-palo-alto-networks/m-p/1000234#M2399</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/471797567"&gt;@kvarshney&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Great explanation in the video !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jan 2025 08:24:49 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2025-01-07T08:24:49Z</dc:date>
    <item>
      <title>Translate Suricata IPS signatures into custom Palo Alto Networks threat signatures</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/translate-suricata-ips-signatures-into-custom-palo-alto-networks/m-p/1000206#M2398</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Threat Prevention&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;goes beyond a typical intrusion prevention system (IPS) to inspect all traffic for threats (regardless of port, protocol, or encryption), and automatically blocks known vulnerabilities, malware, exploits, spyware, and command-and-control. Customers can easily automate workflows to rapidly &lt;STRONG&gt;apply IPS signatures in popular formats such as Snort and Suricata&lt;/STRONG&gt;, and take advantage of our enhanced threat coverage&lt;/SPAN&gt;&lt;STRONG&gt;.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Suricata is an open-source intrusion detection system developed by the Open Information Security Foundation. It can identify complex malicious patterns in network traffic using customizable rules, and therefore it is able to detect sophisticated attacks beyond basic signature-based detection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Suricata is supported by a large community contributing to its development.&amp;nbsp; Therefore, Suricata is used by many organizations as a &lt;STRONG&gt;complementary&lt;/STRONG&gt; security tool to create &lt;STRONG&gt;custom signatures, which are tailored to their environment.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Being an open source tool, it can be easily &lt;STRONG&gt;integrated&lt;/STRONG&gt; into Palo Alto Networks next gen firewalls, using &lt;STRONG&gt;Panorama version 10.0 or higher.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Let us review the process of signature conversion, which is a 3-step process.&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;Install or update the latest &lt;STRONG&gt;IPS Signature Converter&lt;/STRONG&gt; plugin for Panorama.&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Upload&lt;/STRONG&gt; and &lt;STRONG&gt;convert&lt;/STRONG&gt; Suricata signatures into the &lt;STRONG&gt;custom threat signatures&lt;/STRONG&gt;.&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI style="font-weight: 400;" aria-level="1"&gt;&lt;STRONG&gt;Import&lt;/STRONG&gt; them into Panorama, and finally push these to your device group.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Let us dive directly into this &lt;STRONG&gt;&lt;A href="https://youtu.be/wA9J01LqbRk" target="_blank" rel="noopener"&gt;3-steps demo&lt;/A&gt;&lt;/STRONG&gt; …&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jan 2025 23:55:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/translate-suricata-ips-signatures-into-custom-palo-alto-networks/m-p/1000206#M2398</guid>
      <dc:creator>kvarshney</dc:creator>
      <dc:date>2025-01-06T23:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Translate Suricata IPS signatures into custom Palo Alto Networks threat signatures</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/translate-suricata-ips-signatures-into-custom-palo-alto-networks/m-p/1000234#M2399</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/471797567"&gt;@kvarshney&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Great explanation in the video !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jan 2025 08:24:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/translate-suricata-ips-signatures-into-custom-palo-alto-networks/m-p/1000234#M2399</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2025-01-07T08:24:49Z</dc:date>
    </item>
  </channel>
</rss>

