# \#suricata

**URL:** https://community.emergingthreats.net/tag/suricata/9.md

[Latest](https://community.emergingthreats.net/latest.md) · [Categories](https://community.emergingthreats.net/categories.md) · [Tags](https://community.emergingthreats.net/tags.md)

---

## [SIGS: PackClient stream-aware signatures and Core startup correlation](https://community.emergingthreats.net/t/sigs-packclient-stream-aware-signatures-and-core-startup-correlation/3461)

<div class="topic-metadata">

**Author:** [@Ivan](https://community.emergingthreats.net/u/Ivan)\
**Replies:** 0\
**Last updated:** [September 22, 2026, 10:36pm UTC](https://community.emergingthreats.net/t/sigs-packclient-stream-aware-signatures-and-core-startup-correlation/3461 "2026-09-22T22:36:56Z")

</div>

Hi y’all, I REd PackClient and identified a TCP stream robustness issue in the existing ET PackClient Launcher signatures. The current PLH1 / PLC1 / PLA1 / PLK1 detections (ET SIDs 2069878–2069882) rely on packet-bound…

---

## [Why ET rules used hex bytes instead of the original characters?](https://community.emergingthreats.net/t/why-et-rules-used-hex-bytes-instead-of-the-original-characters/3423)

<div class="topic-metadata">

**Author:** [@Sam\_Freeman](https://community.emergingthreats.net/u/Sam_Freeman)\
**Replies:** 4\
**Last updated:** [August 24, 2026, 8:09am UTC](https://community.emergingthreats.net/t/why-et-rules-used-hex-bytes-instead-of-the-original-characters/3423 "2026-08-24T08:09:51Z")

</div>

Hello everyone! While studying the rules from Emerging Threats, I noticed one peculiarity. In the rules, instead of the original symbols (for example, “.”) their hexadecimal byte values are used. Example Rules: alert…

---

## [SIG:ET HUNTING Possible Sliver Age and Minisign Key Material in Internal TCP Stream](https://community.emergingthreats.net/t/sig-et-hunting-possible-sliver-age-and-minisign-key-material-in-internal-tcp-stream/3352)

<div class="topic-metadata">

**Author:** [@Pb-22](https://community.emergingthreats.net/u/Pb-22)\
**Replies:** 0\
**Last updated:** [June 10, 2026, 2:21am UTC](https://community.emergingthreats.net/t/sig-et-hunting-possible-sliver-age-and-minisign-key-material-in-internal-tcp-stream/3352 "2026-06-10T02:21:20Z")

</div>

SIG: ET HUNTING Possible Sliver Age and Minisign Key Material in Internal TCP Stream Hi all, I wanted to share a Suricata hunting rule and an anonymized proof PCAP for review. The rule looks for age style public key mat…

---

## [SIG: EarthWorm Reverse SOCKS Handshake and Tunnel Sequence Detection](https://community.emergingthreats.net/t/sig-earthworm-reverse-socks-handshake-and-tunnel-sequence-detection/3314)

<div class="topic-metadata">

**Author:** [@Pb-22](https://community.emergingthreats.net/u/Pb-22)\
**Replies:** 6\
**Last updated:** [May 27, 2026, 12:42am UTC](https://community.emergingthreats.net/t/sig-earthworm-reverse-socks-handshake-and-tunnel-sequence-detection/3314 "2026-05-27T00:42:18Z")

</div>

EarthWorm Research Lineage, Protocol Grounding, and Sample PCAP Set Hi all, I wanted to share some background on how this research thread came together, the protocol grounding behind the detections, and the sample PCAP s…

---

## [SIG: BPFDoor icmpShell ICMP artifacts from Rapid7 whitepaper](https://community.emergingthreats.net/t/sig-bpfdoor-icmpshell-icmp-artifacts-from-rapid7-whitepaper/3271)

<div class="topic-metadata">

**Author:** [@Pb-22](https://community.emergingthreats.net/u/Pb-22)\
**Replies:** 12\
**Last updated:** [May 14, 2026, 8:50pm UTC](https://community.emergingthreats.net/t/sig-bpfdoor-icmpshell-icmp-artifacts-from-rapid7-whitepaper/3271 "2026-05-14T20:50:08Z")

</div>

@bingohotdog I put together a small BPFDoor ICMP lab and wanted to share a few tested rule ideas based on a recent Rapid7 whitepaper (link in rules). I built a minimal PCAP to exercise the icmpShell related behaviors de…

---

## [Access to ET PRO Rules](https://community.emergingthreats.net/t/access-to-et-pro-rules/3318)

<div class="topic-metadata">

**Author:** [@jannitand](https://community.emergingthreats.net/u/jannitand)\
**Replies:** 2\
**Last updated:** [May 13, 2026, 3:24pm UTC](https://community.emergingthreats.net/t/access-to-et-pro-rules/3318 "2026-05-13T15:24:30Z")

</div>

Hello, Where can I find information about how to subscribe to ET PRO rule updates as well as price information? Thank you!

---

## [SIG: Suspicious File Delivery from Cloudflare Family Host](https://community.emergingthreats.net/t/sig-suspicious-file-delivery-from-cloudflare-family-host/3246)

<div class="topic-metadata">

**Author:** [@Pb-22](https://community.emergingthreats.net/u/Pb-22)\
**Replies:** 7\
**Last updated:** [April 10, 2026, 5:40pm UTC](https://community.emergingthreats.net/t/sig-suspicious-file-delivery-from-cloudflare-family-host/3246 "2026-04-10T17:40:55Z")

</div>

alert http $HOME\_NET any → $EXTERNAL\_NET any (msg:“LOCAL suspicious file delivery from targeted Cloudflare-family host”; flow:to\_server,established; http.host; pcre:“/^(?:(?:\[A-Za-z0-9-\]+.)\*trycloudflare.com|(?:\[A-Za-z0-…

---

## [SIGS: PoC for Axios NPM package supply chain compromise](https://community.emergingthreats.net/t/sigs-poc-for-axios-npm-package-supply-chain-compromise/3248)

<div class="topic-metadata">

**Author:** [@n0pth](https://community.emergingthreats.net/u/n0pth)\
**Replies:** 3\
**Last updated:** [April 1, 2026, 9:47pm UTC](https://community.emergingthreats.net/t/sigs-poc-for-axios-npm-package-supply-chain-compromise/3248 "2026-04-01T21:47:19Z")

</div>

Signature proposal based on the following research One of the most popular JavaScript packages on earth Axios has been compromised | OpenSourceMalware (disclaimer: i’m not the author). NOTE: Signature SIDs need proper a…

---

## [EveBox Issue UI Lag: Logs not updating in Real-time](https://community.emergingthreats.net/t/evebox-issue-ui-lag-logs-not-updating-in-real-time/3230)

<div class="topic-metadata">

**Author:** [@Hoisang](https://community.emergingthreats.net/u/Hoisang)\
**Replies:** 1\
**Last updated:** [March 17, 2026, 8:56pm UTC](https://community.emergingthreats.net/t/evebox-issue-ui-lag-logs-not-updating-in-real-time/3230 "2026-03-17T20:56:28Z")

</div>

I’m facing an issue where EveBox GUI is not displaying logs in real-time. It causes me to miss critical alerts and I have to manually check raw logs/emails instead. Any tips on optimizing EveBox or Elasticsearch for bett…

---

## [Help with Custom Suricata Rule for specific Attack Testing](https://community.emergingthreats.net/t/help-with-custom-suricata-rule-for-specific-attack-testing/3227)

<div class="topic-metadata">

**Author:** [@Hoisang](https://community.emergingthreats.net/u/Hoisang)\
**Replies:** 3\
**Last updated:** [March 13, 2026, 3:28pm UTC](https://community.emergingthreats.net/t/help-with-custom-suricata-rule-for-specific-attack-testing/3227 "2026-03-13T15:28:35Z")

</div>

Hi everyone, I’m trying to create a custom Suricata rule to detect a specific attack test, but it’s not triggering as expected. Could someone review my rule logic based on this traffic pattern?

---

## [Possibly incorrect domain for ET ADWARE\_PUP signature](https://community.emergingthreats.net/t/possibly-incorrect-domain-for-et-adware-pup-signature/3211)

<div class="topic-metadata">

**Author:** [@starbuck](https://community.emergingthreats.net/u/starbuck)\
**Replies:** 2\
**Last updated:** [February 25, 2026, 8:11pm UTC](https://community.emergingthreats.net/t/possibly-incorrect-domain-for-et-adware-pup-signature/3211 "2026-02-25T20:11:20Z")

</div>

Hiya, our team received an alert for the signature ET ADWARE\_PUP Observed DNS Query to Passive Income App Domain (honeybook .com) which when I looked at the signature for contains the following: alert dns $HOME\_NET any…

---

## [Bug: SID 2064326 has severity:1 but is labeled "ET INFO"](https://community.emergingthreats.net/t/bug-sid-2064326-has-severity-1-but-is-labeled-et-info/3171)

<div class="topic-metadata">

**Author:** [@Hans2026](https://community.emergingthreats.net/u/Hans2026)\
**Replies:** 4\
**Last updated:** [January 21, 2026, 3:33pm UTC](https://community.emergingthreats.net/t/bug-sid-2064326-has-severity-1-but-is-labeled-et-info/3171 "2026-01-21T15:33:05Z")

</div>

Rule SID 2064326 “ET INFO Python aiohttp User-Agent Observed Inbound” has conflicting severity indicators, causing false positives in downstream security tools. This rule has: severity: 1 in Suricata alert output (cri…

---

## [Suricata not detecting attacks using emerging threats](https://community.emergingthreats.net/t/suricata-not-detecting-attacks-using-emerging-threats/3100)

<div class="topic-metadata">

**Author:** [@Karl0Ken](https://community.emergingthreats.net/u/Karl0Ken)\
**Replies:** 0\
**Last updated:** [November 4, 2025, 11:38am UTC](https://community.emergingthreats.net/t/suricata-not-detecting-attacks-using-emerging-threats/3100 "2025-11-04T11:38:20Z")

</div>

I am currently working on my thesis, where I need a set of suricata alerts, labeled with event type (benign, attack). For this, I’ve been using the cic-ids2017 data set (https://www.unb.ca/cic/datasets/ids-2017.html). I …

---

## [New Autosuricata Release (September 2025)](https://community.emergingthreats.net/t/new-autosuricata-release-september-2025/3031)

<div class="topic-metadata">

**Author:** [@trobinson667](https://community.emergingthreats.net/u/trobinson667)\
**Replies:** 0\
**Last updated:** [September 12, 2025, 4:53pm UTC](https://community.emergingthreats.net/t/new-autosuricata-release-september-2025/3031 "2025-09-12T16:53:15Z")

</div>

Autosuricata: September 2025 update Hey everyone, quite some time ago, I discussed some side projects of mine that I’ve worked on. I’d like to announce some updates I’ve made to one of those projects, Autosuricata. In a …

---

## [Come Sail the CVEs Part 2: Turning Data Into Rules](https://community.emergingthreats.net/t/come-sail-the-cves-part-2-turning-data-into-rules/2751)

<div class="topic-metadata">

**Author:** [@trobinson667](https://community.emergingthreats.net/u/trobinson667)\
**Replies:** 0\
**Last updated:** [May 21, 2025, 6:57pm UTC](https://community.emergingthreats.net/t/come-sail-the-cves-part-2-turning-data-into-rules/2751 "2025-05-21T18:57:14Z")

</div>

Come Sail the CVEs Part 2: Turning Data Into Rules Note: This post contains proof of concept exploits for several different platforms, both embedded in the post, as well as available through links in the post. Please act…

---

## [Commented Out Rules](https://community.emergingthreats.net/t/commented-out-rules/2711)

<div class="topic-metadata">

**Author:** [@BOBIBOO](https://community.emergingthreats.net/u/BOBIBOO)\
**Replies:** 2\
**Last updated:** [May 7, 2025, 8:00pm UTC](https://community.emergingthreats.net/t/commented-out-rules/2711 "2025-05-07T20:00:59Z")

</div>

Hello, I’m an undergraduate student in South Korea currently working on a malware detection system using Suricata. While reviewing the ET Open Ruleset, I noticed that some rules are commented out (i.e., disabled with #)…

---

## [PCRE in Sitecore CMS CSRFTOKEN Deserialization sid:2061119 for CVE-2019-9874](https://community.emergingthreats.net/t/pcre-in-sitecore-cms-csrftoken-deserialization-sid-2061119-for-cve-2019-9874/2575)

<div class="topic-metadata">

**Author:** [@rampage](https://community.emergingthreats.net/u/rampage)\
**Replies:** 1\
**Last updated:** [March 27, 2025, 6:28pm UTC](https://community.emergingthreats.net/t/pcre-in-sitecore-cms-csrftoken-deserialization-sid-2061119-for-cve-2019-9874/2575 "2025-03-27T18:28:45Z")

</div>

Hi, Friends! The PoC payload snippet disclosed in https://www.synacktiv.com/ressources/advisories/Sitecore\_CSRF\_deserialize\_RCE.pdf is a base64 encoded string. “\_\_CSRFTOKEN=/wEysRIAAQAAAP////8BAAAAAAAAAAwCAAAASVN5c3Rlb…

---

## [When loading rules for SID 2060960, 2060961, the message 'fast\_pattern is ineffective with base64\_data' occurs](https://community.emergingthreats.net/t/when-loading-rules-for-sid-2060960-2060961-the-message-fast-pattern-is-ineffective-with-base64-data-occurs/2562)

<div class="topic-metadata">

**Author:** [@won2852](https://community.emergingthreats.net/u/won2852)\
**Replies:** 1\
**Last updated:** [March 25, 2025, 4:51pm UTC](https://community.emergingthreats.net/t/when-loading-rules-for-sid-2060960-2060961-the-message-fast-pattern-is-ineffective-with-base64-data-occurs/2562 "2025-03-25T16:51:23Z")

</div>

When loading rules for SIDs 2060960, 2060961, it throws the message ‘fast\_pattern is ineffective with base64\_data’. alert http $HOME\_NET any → $EXTERNAL\_NET any (msg:“ET WEB\_SPECIFIC\_APPS xml-crypto / Node.js SAML Authe…

---

## [Suricata/ET Pro picked this up, help diagnosing please](https://community.emergingthreats.net/t/suricata-et-pro-picked-this-up-help-diagnosing-please/2557)

<div class="topic-metadata">

**Author:** [@jacgfxgeek](https://community.emergingthreats.net/u/jacgfxgeek)\
**Replies:** 2\
**Last updated:** [March 25, 2025, 12:18am UTC](https://community.emergingthreats.net/t/suricata-et-pro-picked-this-up-help-diagnosing-please/2557 "2025-03-25T00:18:28Z")

</div>

Hi I am a new subscriber to ET Pro Telemetry, and a new Opnsense user, so please feel free to enlighten me. Yesterday I installed ET Pro and today I got the following alert. I have searched online, but results are slim…

---

## [CISA\_KEV and you](https://community.emergingthreats.net/t/cisa-kev-and-you/2404)

<div class="topic-metadata">

**Author:** [@trobinson667](https://community.emergingthreats.net/u/trobinson667)\
**Replies:** 0\
**Last updated:** [January 30, 2025, 5:01pm UTC](https://community.emergingthreats.net/t/cisa-kev-and-you/2404 "2025-01-30T17:01:45Z")

</div>

Hey Hey, people. We’re introducing a new metadata tag to the ET ruleset, CISA\_KEV. The purpose of this tag is to identify rules in the ETOPEN and ETPRO rulesets that serve to detect CVEs that have been identified as a p…

---

## [Grimresource transformNode Obfuscation](https://community.emergingthreats.net/t/grimresource-transformnode-obfuscation/2037)

<div class="topic-metadata">

**Author:** [@rampage](https://community.emergingthreats.net/u/rampage)\
**Replies:** 5\
**Last updated:** [October 10, 2024, 6:35pm UTC](https://community.emergingthreats.net/t/grimresource-transformnode-obfuscation/2037 "2024-10-10T18:35:39Z")

</div>

Hello. I’d like to share a rule with the community and welcome feedback. I intend it to detect the transformNode Obfuscation used in the Grimresource sample analyzed by Elastic Security Labs GrimResource - Microsoft Man…

---

## [Private TryHackMe Suricata Room by Emerging Threats](https://community.emergingthreats.net/t/private-tryhackme-suricata-room-by-emerging-threats/1973)

<div class="topic-metadata">

**Author:** [@bingohotdog](https://community.emergingthreats.net/u/bingohotdog)\
**Replies:** 0\
**Last updated:** [September 12, 2024, 11:48pm UTC](https://community.emergingthreats.net/t/private-tryhackme-suricata-room-by-emerging-threats/1973 "2024-09-12T23:48:41Z")

</div>

Hello Emerging Threats Community, The Emerging Threats team and eatinsundip have released a private TryHackMe Suricata room. It’s available and accessible for registered users here, TryHackMe | Cyber Security Training o…

---

## [DiamotrixClipper](https://community.emergingthreats.net/t/diamotrixclipper/1925)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 2\
**Last updated:** [August 30, 2024, 9:08pm UTC](https://community.emergingthreats.net/t/diamotrixclipper/1925 "2024-08-30T21:08:33Z")

</div>

Hi, together with @g0njxa we found a loader(Sniffthem/Tnaket) and a clipper (Diamotrix) here is the signature for the clipper: URI: alert http any any -\> any any (msg: "ET MALWARE \[ANY.RUN\] Request a wallet for Diamo…

---

## [Suricata IDS probe on NanoBSD](https://community.emergingthreats.net/t/suricata-ids-probe-on-nanobsd/1117)

<div class="topic-metadata">

**Author:** [@JoshT](https://community.emergingthreats.net/u/JoshT)\
**Replies:** 1\
**Last updated:** [August 23, 2024, 7:23am UTC](https://community.emergingthreats.net/t/suricata-ids-probe-on-nanobsd/1117 "2024-08-23T07:23:12Z")

</div>

Hi All, My first post but thought I’d share as I’ve not seen anyone else doing something similar. I’ve build a NanoBSD image (embedded version of FreeBSD) on a PC Engines APU solely to run Suricata; its working great a…

---

## [NjRAT variant - tXRAT v.2.3R](https://community.emergingthreats.net/t/njrat-variant-txrat-v-2-3r/1746)

<div class="topic-metadata">

**Author:** [@Jane0sint](https://community.emergingthreats.net/u/Jane0sint)\
**Replies:** 1\
**Last updated:** [June 21, 2024, 4:44pm UTC](https://community.emergingthreats.net/t/njrat-variant-txrat-v-2-3r/1746 "2024-06-21T16:44:11Z")

</div>

Hi, recently I discovered a modification of the famous rat NjRat, we could not detect it with the existing rules, so I propose several new ones (version obtained from traffic) NjRat Traffic example 155.ll|‘|’|VEVTVF9D…

---

## [Doc.emergingthreats.net, Reference information](https://community.emergingthreats.net/t/doc-emergingthreats-net-reference-information/1191)

<div class="topic-metadata">

**Author:** [@Oppressed1192](https://community.emergingthreats.net/u/Oppressed1192)\
**Replies:** 5\
**Last updated:** [March 18, 2024, 9:25pm UTC](https://community.emergingthreats.net/t/doc-emergingthreats-net-reference-information/1191 "2024-03-18T21:25:55Z")

</div>

Hello, I’m new to the Suricata world, and I keep seeing ET rules with references to the subdomain doc, however, this subdomain doesn’t resolve. Where can I find more information on specific SIDs that are in the Emerging …

---

## [IDS and IPS rules on LAN](https://community.emergingthreats.net/t/ids-and-ips-rules-on-lan/1300)

<div class="topic-metadata">

**Author:** [@hacked](https://community.emergingthreats.net/u/hacked)\
**Replies:** 1\
**Last updated:** [January 22, 2024, 6:05pm UTC](https://community.emergingthreats.net/t/ids-and-ips-rules-on-lan/1300 "2024-01-22T18:05:41Z")

</div>

Hi, I’m interesting to do IDS and IPS on the inside of my network using Suricata. I have trouble of as an exampe of detecting nmap scans and having a look at the example rule below: alert tcp $EXTERNAL\_NET any → $HOME\_…

---

## [Get Started with Suricata CLI Debugging](https://community.emergingthreats.net/t/get-started-with-suricata-cli-debugging/1195)

<div class="topic-metadata">

**Author:** [@bingohotdog](https://community.emergingthreats.net/u/bingohotdog)\
**Replies:** 0\
**Last updated:** [December 11, 2023, 10:09pm UTC](https://community.emergingthreats.net/t/get-started-with-suricata-cli-debugging/1195 "2023-12-11T22:09:44Z")

</div>

Let’s review how to debug Suricata rules from the command line. If you want to troubleshoot your rules or the Suricata engine itself, then CLI debugging is an invaluable skill to have! The following Suricata bug inspir…

---

## [False positive on Android Trojan](https://community.emergingthreats.net/t/false-positive-on-android-trojan/1053)

<div class="topic-metadata">

**Author:** [@michmoor](https://community.emergingthreats.net/u/michmoor)\
**Replies:** 1\
**Last updated:** [October 19, 2023, 7:34pm UTC](https://community.emergingthreats.net/t/false-positive-on-android-trojan/1053 "2023-10-19T19:34:15Z")

</div>

Greetings everyone, Im writing to see what is the best way to report a false positive on a signature. Signature: ET JA3 Hash - Trojan.AndroidOS.Jocker.snt 1 Background: Seeking advice on next steps in investigation | …

---

## [Want to get started with NSM? I have a few projects for you (Building Virtual Machine Labs, Autosnort3, Autosuricata)](https://community.emergingthreats.net/t/want-to-get-started-with-nsm-i-have-a-few-projects-for-you-building-virtual-machine-labs-autosnort3-autosuricata/1043)

<div class="topic-metadata">

**Author:** [@trobinson667](https://community.emergingthreats.net/u/trobinson667)\
**Replies:** 0\
**Last updated:** [October 16, 2023, 6:50pm UTC](https://community.emergingthreats.net/t/want-to-get-started-with-nsm-i-have-a-few-projects-for-you-building-virtual-machine-labs-autosnort3-autosuricata/1043 "2023-10-16T18:50:50Z")

</div>

Hey folks I wanted to share a little bit of information about some side projects that I have been maintaining for a few years. Building Virtual Machine Labs: A Hands-on Guide First and foremost, I wrote a book called B…

[Next page](https://community.emergingthreats.net/tag/suricata/9.md?match_all_tags=true&page=1&tags%5B%5D=suricata)
