Custom Signatures
The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Custom Signatures
The Custom Signatures discussion is a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance.
About Custom Signatures

Welcome to the Custom Signatures discussion forum. This forum exists as a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance. Please feel free to engage with other community members and Palo Alto Networks staff. Ideas, questions, research, and observations regarding the process of custom signature creation are all actively encouraged.

For an introduction to the forum, please see the sticky!

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to custom signatures. Please use the information from this forum at your own risk and make sure to test and verify any signature and code presented here. For information on contacting Palo Alto Networks support, click here.

Discussions

Regex for syslog User-ID not working

Hi team,

 

We have the (Cisco & Ruckus) Wireless controllers forwarding SYSLOGS to the User-ID agent running on Windows 2012 server.

 

We want to use these syslog messages to create user-ip mappings. We tried with several different regex patterns but not

...

ansharma by L4 Transporter
  • 2267 Views
  • 2 replies
  • 0 Likes

Custom data pattern

Hi Team 

 

I have a user who has a requirement to add a custom Data Pattern to identify a specific string 

 

Example: 1234/09/4578 

 

(Note the second identifier is a numeric value between [1-9])

 

I set up the data pattern under " Custom Objects --->Data Pa

...

agawade by L1 Bithead
  • 1941 Views
  • 2 replies
  • 0 Likes

Resolved! Submitting DNS block without blocking the IP

I'm looking to submit a FQDN block where I don't ever block the IP.

 

I've reviewed this article on blocking FQDN's but can't seem to figure out how to ignore the IP. We assign fake ip addresses to known malicius sites, and need the HTTP, HTTPS, SSH, e

...

Wordpress wp-login.php flood

Today we built a custom vulnerability signature to block excessive request from one IP to wp-login.php. 

 

 wp-login.php thread-id 42106wp-login.php thread-id 42106wp-login.php thread-id 42106wp-login.php flood threat-id 42107wp-login.php flood threat-

...

42106-1.PNG
42106-2.PNG
42106-3.PNG
wp1.PNG
PortsIT by L0 Member
  • 1905 Views
  • 0 replies
  • 2 Likes
Top Liked Authors
Labels