Basic Rule to Detect/Alert on OvenVas Scanners

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Basic Rule to Detect/Alert on OvenVas Scanners

L1 Bithead

So I'm surprised that the Palo Alto doesn't have a signature to detect OpenVAS scanners. I would like to create a simple rule that detects "User-Agent: OpenVAS" (Ultimately I would like to just block these entirely.

 

Is something that can be easily built?

2 REPLIES 2

L7 Applicator

Please refer to the thread on this forum:

https://live.paloaltonetworks.com/t5/Custom-Signatures/Welcome-to-the-Palo-Alto-Networks-Custom-Sign...

This has an example on how to detect Nikto Scanner traffic by sigging off the user-agent:

Example 2: Detecting Nikto Scans through User Agent (Nikto User Agent.xml)

 

The same thing can be achieved for OpenVAS by simply modifying the value in the user-agent field in the signature to "OpenVAS".

 

The signature can then be used in policy to alert/block etc.

I could not get the OpenVAS signature to work by just switching Nikto for OpenVAS. I had to do a more basic string <pattern>OpenVAS</pattern> . I actually did <pattern>OpenVAS 8</pattern> at first to see if that would work, it did. (OpenVAS 8.0.9 was the user agent. 

 

Make sure you edit the entry name if you use my .xml file. You might already have that number in use. Also created one for Baiduspider since my IDS picked it up in a scan and I saw the user agent string for it. 

 

There's a few useful links that will show user agent strings for popular scanners/crawlers. 

 

https://developers.whatismybrowser.com/useragents/explore/software_type_specific/crawler/9
http://www.useragentstring.com/pages/useragentstring.php?typ=Crawler

 

Hope that helps, thanks -Rags

  • 5085 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!