<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Community or News Group that has taken Snort signatures and converted them to PaloAlto in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/community-or-news-group-that-has-taken-snort-signatures-and/m-p/255955#M529</link>
    <description>&lt;P&gt;Please refer to:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/threat-prevention/custom-signatures.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/threat-prevention/custom-signatures.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Apr 2019 18:04:38 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2019-04-03T18:04:38Z</dc:date>
    <item>
      <title>Community or News Group that has taken Snort signatures and converted them to PaloAlto</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/community-or-news-group-that-has-taken-snort-signatures-and/m-p/253738#M507</link>
      <description>&lt;P&gt;This is a very easy question for everybody.&amp;nbsp; A lot of people have most likely created custom signatures from Snort or otherwise to apply to a PaloAlto firewall.&amp;nbsp; Does anyone know of a news group or community in which those signatures have been converted and that you can download free of charge?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, does anyone know of a list that (to the best of their ability) matches a Snort signature that is natively included in the Snort feeds and their PaloAlto equivalents?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Finally, are there regex examples that define things like the offset of of the IP header, or Ethernet header or TCP header, etc.&amp;nbsp; I would like to include some of that stuff in a RegEx definition when writing a regex?&amp;nbsp; In addition to this, how do you write a RedEx that masks a byte so you can pull out bit information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know this is a long list, but any and all assistance would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 16:12:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/community-or-news-group-that-has-taken-snort-signatures-and/m-p/253738#M507</guid>
      <dc:creator>ScottF</dc:creator>
      <dc:date>2019-03-14T16:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Community or News Group that has taken Snort signatures and converted them to PaloAlto</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/community-or-news-group-that-has-taken-snort-signatures-and/m-p/255955#M529</link>
      <description>&lt;P&gt;Please refer to:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/threat-prevention/custom-signatures.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/threat-prevention/custom-signatures.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2019 18:04:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/community-or-news-group-that-has-taken-snort-signatures-and/m-p/255955#M529</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2019-04-03T18:04:38Z</dc:date>
    </item>
  </channel>
</rss>

