<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Snort Signature in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/custom-snort-signature/m-p/386591#M90276</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110" target="_blank" rel="noopener"&gt;@Mohammed_Yasin&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To actually respond to your question: http_method in the Custom Vulnerability Object is the&amp;nbsp;http-method&amp;nbsp;Qualifier and the&amp;nbsp;http_client_body is the&amp;nbsp;http-req-message-body&amp;nbsp;Context, i.e.,:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CCACieszkowski_0-1613655082750.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29987i56A997CB3A721C07/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CCACieszkowski_0-1613655082750.png" alt="CCACieszkowski_0-1613655082750.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Albert&lt;/P&gt;</description>
    <pubDate>Thu, 18 Feb 2021 13:33:43 GMT</pubDate>
    <dc:creator>CCACieszkowski</dc:creator>
    <dc:date>2021-02-18T13:33:43Z</dc:date>
    <item>
      <title>Custom Snort Signature</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-snort-signature/m-p/354713#M87466</link>
      <description>&lt;P&gt;creating a custom snort signature on Palo alto Firewall but didn’t found the concern context operator for match pattern.&lt;/P&gt;&lt;P&gt;Shall we create a context operator or how it can add the pattern if the context operator is not available?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET 443 (msg:"[CIS] Emotet C2 Traffic Using Form Data to Send Passwords"; content:"POST"; &lt;FONT color="#FF6600"&gt;http_method&lt;/FONT&gt;; content:"&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;Content-Type|3a 20|multipart/form-data|3b 20|boundary=&lt;/FONT&gt;&lt;/STRONG&gt;"; http_header; fast_pattern; content:"Content-Disposition|3a 20|form-data|3b 20|name=|22|"; http_client_body; content:!"------WebKitFormBoundary"; &lt;FONT color="#FF6600"&gt;http_client_body&lt;/FONT&gt;; content:!"&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Cookie|3a|"; pcre:"/:?(chrome|firefox|safari|opera|ie|edge) passwords/i&lt;/STRONG&gt;&lt;/FONT&gt;"; reference:url,cofen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Not available&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Snort.jpg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28122i3CF2023AB6D5D061/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Snort.jpg" alt="Snort.jpg" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;SPAN&gt;HTTP _ method&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;HTTP _ client_body&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 07:12:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-snort-signature/m-p/354713#M87466</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-10-07T07:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Snort Signature</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-snort-signature/m-p/354956#M87489</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The problem with custom signatures is that they are not dynamic. I would say configure the PAN with best practices and enable, Anti-Virus, Vulnerability, URL Filtering, DNS SinkHole, wildfire, secure DNS, SSL decryption, etc. Alsong with this enable sending telemetry back to PAN for statistics, this also helps build new signatures etc. This should protect you from most of everything. In your example you have Emotet, and if you look at the threat vault there are already many signatures for it.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" target="_blank"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are also External Dynamic lists and other things you can do as an overarching strategy, static entries are a major pain and hard to keep up with. Perhaps also implement another IDS to supplement you security posture?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 19:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-snort-signature/m-p/354956#M87489</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-10-07T19:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Snort Signature</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-snort-signature/m-p/354982#M87497</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110"&gt;@Mohammed_Yasin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Just to add on to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentioned, you aren't going to have a one to one match on a snort rule when you attempt to map them via a custom signature. The terminology isn't the same at all, but generally speaking every option you are looking for is going to be present. The real change here is that PAN separates a lot of this information between request and response, so in a lot of situations you'll actually have to know the direction of traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I wouldn't recommend building a custom threat signature unless you actually&amp;nbsp;&lt;EM&gt;need&amp;nbsp;&lt;/EM&gt;to within your environment. So the Snort rule that you pulled from MS-ISAC is an example of what Snort can look at, but PAN is already providing more than 200+ signatures to detect emotet related traffic and threats. If I really wanted to take every single Snort rule that they built out to ensure we were covered from the threat, I would simply install a snort node.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2020 21:22:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-snort-signature/m-p/354982#M87497</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-07T21:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Snort Signature</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/custom-snort-signature/m-p/386591#M90276</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131110" target="_blank" rel="noopener"&gt;@Mohammed_Yasin&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To actually respond to your question: http_method in the Custom Vulnerability Object is the&amp;nbsp;http-method&amp;nbsp;Qualifier and the&amp;nbsp;http_client_body is the&amp;nbsp;http-req-message-body&amp;nbsp;Context, i.e.,:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CCACieszkowski_0-1613655082750.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29987i56A997CB3A721C07/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CCACieszkowski_0-1613655082750.png" alt="CCACieszkowski_0-1613655082750.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Albert&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 13:33:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/custom-snort-signature/m-p/386591#M90276</guid>
      <dc:creator>CCACieszkowski</dc:creator>
      <dc:date>2021-02-18T13:33:43Z</dc:date>
    </item>
  </channel>
</rss>

