Advertisement
travisbgreen

Untitled

Aug 9th, 2019
242
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.22 KB | None | 0 0
  1. Rules:
  2.  
  3. alert tcp any any -> $HOME_NET any (msg:"TGI LATERAL DCERPC ATSVC v1.0 Bind UUID 1ff70682-0a51-30e8-076d-740be8cee98b"; flow:established; dce_iface:1ff70682-0a51-30e8-076d-740be8cee98b,any_frag; reference:url,401trg.com/an-introduction-to-smb-for-network-security-analysts/; classtype:attempted-admin; sid:2610115; rev:1; metadata:notworking;)
  4.  
  5. alert tcp any any -> $HOME_NET any (msg:"TGI LATERAL DCERPC ATSVC v1.0 Bind UUID"; flow:established; content:"|82 06 f7 1f 51 0a e8 30 07 6d 74 0b e8 ce e9 8b|"; reference:url,401trg.com/an-introduction-to-smb-for-network-security-analysts/; classtype:attempted-admin; sid:2610113; rev:1;)
  6.  
  7. alert tcp any any -> $HOME_NET any (msg:"TGI LATERAL DCERPC ATSVC v1.0 JobAdd (Opnum 0)"; flow:established; content:"|05 00 00|"; content:"|00 00|"; distance:19; within:2; content:"|82 06 f7 1f 51 0a e8 30 07 6d 74 0b e8 ce e9 8b|"; distance:0; reference:url,401trg.com/an-introduction-to-smb-for-network-security-analysts/; classtype:attempted-admin; sid:2610114; rev:1;)
  8.  
  9.  
  10. sudo /home/user/projects/suri_docs/suricata-git.latest/src/suricata -c /home/user/projects/suri_docs/suricata-git.latest/suricata.yaml -S ./documentation.rules -r ./merged.pcap -l . -k none && cat ./fast.log
  11. [14304] 9/8/2019 -- 15:43:50 - (suricata.c:1071) <Notice> (LogVersion) -- This is Suricata version 5.0.0-dev (3a912446a 2019-07-22) running in USER mode
  12. [14304] 9/8/2019 -- 15:43:50 - (tm-threads.c:2145) <Notice> (TmThreadWaitOnThreadInit) -- all 9 packet processing threads, 4 management threads initialized, engine started.
  13. [14304] 9/8/2019 -- 15:43:50 - (suricata.c:2851) <Notice> (SuricataMainLoop) -- Signal Received. Stopping engine.
  14. [14318] 9/8/2019 -- 15:43:50 - (source-pcap-file.c:378) <Notice> (ReceivePcapFileThreadExitStats) -- Pcap-file module read 1 files, 20 packets, 3272 bytes
  15. 10/20/2017-12:43:22.992817 [**] [1:2610113:1] TGI LATERAL DCERPC ATSVC v1.0 Bind UUID [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 192.168.10.31:49266 -> 192.168.10.30:445
  16. 10/20/2017-12:43:22.992817 [**] [1:2610114:1] TGI LATERAL DCERPC ATSVC v1.0 JobAdd (Opnum 0) [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 192.168.10.31:49266 -> 192.168.10.30:445
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement