Custom Signatures
cancel
Showing results for 
Search instead for 
Did you mean: 
Custom Signatures
About Custom Signatures

Welcome to the Custom Signatures discussion forum. This forum exists as a resource for security professionals to discuss the creation process of custom signatures in their PAN-OS appliance. Please feel free to engage with other community members and Palo Alto Networks staff. Ideas, questions, research, and observations regarding the process of custom signature creation are all actively encouraged.

For an introduction to the forum, please see the sticky!

Disclaimer:
This forum is provided for Live Community members to discuss and share information pertaining to custom signatures. Please use the information from this forum at your own risk and make sure to test and verify any signature and code presented here. For information on contacting Palo Alto Networks support, click here.

Forum Posts

Resolved! Case insensitive Regex expression

I am creating a regex to capture on the expression "Bank of America". I am having trouble getting case insensitivity to work so that I can capture on "Bank of America, bank of america or any other variation. What is the format of this expression to a...

ttanzi by L2 Linker
  • 1708 Views
  • 2 replies
  • 0 Likes

Resolved! RegEx - Pattern for strange string not work

Someone can help me for this pattern? PATTERN: +-----------------------------------------------------------------------+ PATTERN in Hex: 2b 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d...

Need help with creating signature for pop3

I would need some assistance with setting up a custom signature for pop3. I need to make a signature for the USER command returning "-ERR " currently the Pan vuln signature only triggers on the Pass command in vuln id 31709. I run into a fundamental ...

apike by L1 Bithead
  • 3789 Views
  • 6 replies
  • 0 Likes

Limiting File Size Upload using Custom Signature

Users in enterprise often use web based file hosting to upload big files. This creates concerns in the usage of networks bandwidth and server storage capacity, as the file can be bigger than 1GB. Below steps are usefull to control file size uploaded ...

1.1.jpg
1.2.jpg
1.3.png
1.4.jpg

Detect random sub-domain DNS query

Hello, I would like know if anyone has succesfull creating a custom signature either Custom spyware object or custom vulnerability signature to detect random sub-domain in DNS query. For example: We don't want to block www.yahoo.com or yahoo.com doma...

custom mail app-id

hi. I'am trying to create a custom mail app-id filter, for matching; to whom mail is gonging to and from what domain. I have add smtp as a parent application in the app-id. My app-id is matching the helo, mail from, rcp, data. from the mail. The poli...

application-smtp
application-ports
application-signature
policy-rule
klokholm by L1 Bithead
  • 779 Views
  • 0 replies
  • 0 Likes

Resolved! Joomla Remote Code Execution - CVE-2015-8562

Hello, I created a custom vulnerability signature that helps to detect and block the recently discovered Joomla RCE zero day which has since been patched by the vendor. I've opened a case with an engineer and he suggesed some additional protections u...

kalakai by L2 Linker
  • 2679 Views
  • 1 replies
  • 3 Likes

Submit a New Threat

Hello, My IDS has detected a new Angler signature on my network and it was allowed by my PA firewall. The traffic was allowed being the IDS is not inline. How do I submit packets for a threat update/addition?

bkluth by L0 Member
  • 1771 Views
  • 4 replies
  • 0 Likes

PAN-OS 7.0.3 bug with Cloning of Profiles

Ran into an issue here tonight where when you clone a profile for anti spyware and pattern match based on that, this is broken and will not alert. Be sure to create a new profile from scratch. I have submitted this to Palo for them to vet this issue ...

How to make custom signature with segment field?

Recently, URL filter evasion application often use tcp segment field. How to make custom application with tcp segment field? Protocol sequence. 1. SYN 2. SYN,ACK 3. ACK 4. PSH,ACK : TCP segment data has GET / HTTP/1.1 It can bypass our URL filtering....

dodgechrome_tcp_segment.png
bkim by L0 Member
  • 2063 Views
  • 2 replies
  • 0 Likes

h323-message-body values

We seem to have a new h.225/h.323 scanning campaign going on that disturbs meetings. The strings that seem to be the same throughout are "productId: MERA RTU" and "versionId: 4.4.0-06a". So I've tried two different methods of catching this traffic. C...

Screenshot 2015-11-26 16.21.20.png
Froning by L1 Bithead
  • 1675 Views
  • 6 replies
  • 0 Likes

Dell Root Certificate "eDellRoot"

Good afternoon, all! Researchers have discovered a trusted root certificate being deployed by Dell on some newer laptops. For reference, see here. While an official signature from Palo Alto Networks is likely not forthcoming due to legitimate usage o...

rcole by L4 Transporter
  • 1216 Views
  • 0 replies
  • 3 Likes
Top Liked Authors
Labels