# Suricata/ET Pro picked this up, help diagnosing please

**URL:** <https://community.emergingthreats.net/t/suricata-et-pro-picked-this-up-help-diagnosing-please/2557>\
**Category:** Feedback & Support\
**Tags:** suricata\
**Created:** [March 24, 2025, 12:10am UTC](https://community.emergingthreats.net/t/suricata-et-pro-picked-this-up-help-diagnosing-please/2557 "2025-03-24T00:10:26Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [March 24, 2025, 10:53pm UTC](https://community.emergingthreats.net/t/suricata-et-pro-picked-this-up-help-diagnosing-please/2557/2 "2025-03-24T22:53:20Z")

</div>

Hello and welcome @jacgfxgeek!

When triaging a rule that you aren’t sure about one of the best places to start is by identifying the category which will give you a quick idea of what type of traffic the rule is looking for. Categories are always in uppercase and the second word in the rule title (i.e. `ET INFO` is the `INFO` category). For example these are a few different categories in the ruleset today.

- `INFO`
- `MALWARE`
- `ADWARE_PUP`

We have comprehensive descriptions for each category that you can read here: [Suricata 5, 6, & 7 Rule Categories](https://community.emergingthreats.net/t/suricata-5-6-7-rule-categories/94) . Because this rule is `INFO` that means that this rule is mostly used for audit/correlation purposes. While useful within the context of an investigation they can be a somewhat noisy and do not necessarily indicate a compromise.

Additionally if you view the full rule text you can see that the `severity` is set to `informational` as well. We have signature severity documented here [Rules Severities](https://community.emergingthreats.net/t/rules-severities/337)

Now, on to what the rest of the rule means!

`Cloudflare Page Developer Domain (pages .dev in TLS SNI)` This is indicating that a domain ending in `.pages.dev` was observed during a TLS handshake. This domain is related to a CloudFlare service called “Pages” which is used to quickly stand up websites. We have observed attackers abusing this service in the past for phishing and payload delivery which is why the rule was created. That being said, it is a legitimate service which is widely utilized.

If you want to learn more about our TLS/DNS signatures @trobinson667 has put together an awesome summary that is worth a read through. [Investigating and Interpreting TLS SNI and DNS query rules](https://community.emergingthreats.net/t/investigating-and-interpreting-tls-sni-and-dns-query-rules/543)

`TL/DR:`

- This is an informational rule and does not indicate that malware has been observed so further action may not be needed
- I shared a couple of our resources for understanding rules but we are always happy to answer questions and feedback here!

Let me know if that clears anything up or if you have additional questions.

Thanks!  
Isaac

---

_[View the full topic](https://community.emergingthreats.net/t/suricata-et-pro-picked-this-up-help-diagnosing-please/2557)._
