# Help with Custom Suricata Rule for specific Attack Testing

**URL:** <https://community.emergingthreats.net/t/help-with-custom-suricata-rule-for-specific-attack-testing/3227>\
**Category:** Tutorials, Tips & Tricks\
**Tags:** suricata\
**Created:** [March 12, 2026, 9:17am UTC](https://community.emergingthreats.net/t/help-with-custom-suricata-rule-for-specific-attack-testing/3227 "2026-03-12T09:17:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hoisang](https://avatars.discourse-cdn.com/v4/letter/h/c57346/32.png) [@Hoisang](https://community.emergingthreats.net/u/Hoisang)\
**Post date:** [March 12, 2026, 9:17am UTC](https://community.emergingthreats.net/t/help-with-custom-suricata-rule-for-specific-attack-testing/3227/1 "2026-03-12T09:17:28Z")

</div>

Hi everyone, I’m trying to create a custom Suricata rule to detect a specific attack test, but it’s not triggering as expected. Could someone review my rule logic based on this traffic pattern?

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [March 12, 2026, 8:45pm UTC](https://community.emergingthreats.net/t/help-with-custom-suricata-rule-for-specific-attack-testing/3227/2 "2026-03-12T20:45:26Z")

</div>

Hi @Hoisang!

I’m happy to take a look! Can you share your rule and details about what you’re trying to detect? If you have a pcap that you can share it will make troubleshooting easier.

Thanks,  
Isaac

---

<div class="post-metadata">

**Author:** ![Hoisang](https://avatars.discourse-cdn.com/v4/letter/h/c57346/32.png) [@Hoisang](https://community.emergingthreats.net/u/Hoisang)\
**Post date:** [March 13, 2026, 4:00am UTC](https://community.emergingthreats.net/t/help-with-custom-suricata-rule-for-specific-attack-testing/3227/3 "2026-03-13T04:00:59Z")

</div>

## Config Rule

alert icmp any any → any any (msg:“ICMP Ping Scan Detected Test!!!”; itype:8; classtype:network-scan; sid:1000001; rev:1;)

Log from fast.log on Suricata server  
03/12/2026-17:11:09.885411 [**] [1:1000001:1] ICMP Ping Scan Detected Test!!! [**] [Classification: Detection of a Network Scan] [Priority: 3] {ICMP} 61.91.39.154:8 → 103.255.13.211:0  
03/12/2026-17:11:10.894700 [**] [1:1000001:1] ICMP Ping Scan Detected Test!!! [**] [Classification: Detection of a Network Scan] [Priority: 3] {ICMP} 61.91.39.154:8 → 103.255.13.211:0  
03/12/2026-17:11:11.900386 [**] [1:1000001:1] ICMP Ping Scan Detected Test!!! [**] [Classification: Detection of a Network Scan] [Priority: 3] {ICMP} 61.91.39.154:8 → 103.255.13.211:0  
03/12/2026-17:11:12.910106 [**] [1:1000001:1] ICMP Ping Scan Detected Test!!! [**] [Classification: Detection of a Network Scan] [Priority: 3] {ICMP} 61.91.39.154:8 → 103.255.13.211:0

This is information about Config Rule and Log from Suricata server so it is detect priority 3. But I want detect priority 1 or 2 to use cocept Ping IP Dest. Do you have any another solution? Can we tell me pleases.

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [March 13, 2026, 3:28pm UTC](https://community.emergingthreats.net/t/help-with-custom-suricata-rule-for-specific-attack-testing/3227/4 "2026-03-13T15:28:35Z")

</div>

What you’ll want to do is edit your [Classification Config](https://github.com/OISF/suricata/blob/main/etc/classification.config). Here you can change the priority for each alert type.  
In my suricata install it is located at `/usr/local/etc/suricata/classification.config` but it may be different on your system.

By default the classtype for `network-scan` is a priority 3 but you could change that to whatever you want. Here is a snippet from that config file.

```auto
# config classification:shortname,short description,priority
config classification: network-scan,Detection of a Network Scan,3

```
