Snort mailing list archives

Re: Using DNS response fields in an alert msg


From: "Joel Esler (jesler)" <jesler () cisco com>
Date: Wed, 7 Jan 2015 17:29:24 +0000

X-Forwarded-For (and others) are supported in Snort and are placed in unified2.

--
Joel Esler
Open Source Manager
Threat Intelligence Team Lead
Talos

On Jan 7, 2015, at 9:53 AM, Rodgers, Anthony (DTMB) <RodgersA1 () michigan gov> wrote:

In similar vein, I'd love to do something with the "X-Forwarded-For" header field in HTTP traffic. For suspected 
infections, it's the proxy client I'm interested in remediating, not the proxy server itself.

Perhaps this is something to take to the oisf-users list.

Anthony Rodgers
Security Analyst
Michigan Security Operations Center (MiSOC)

-----Original Message-----
From: lists () packetmail net [mailto:lists () packetmail net] 
Sent: Wednesday, January 07, 2015 09:06
To: snort-sigs () lists sourceforge net
Subject: Re: [Snort-sigs] Using DNS response fields in an alert msg

On 01/07/2015 07:19 AM, David Longenecker wrote:
Does anyone on this list have an example of snort parsing a dns 
response into its component name and address fields, and using these fields in the alert message?

Sadly, for this use case this is simply something that Snort is not capable of doing.  Perhaps something like 
Suricata would be useful where you can couple the alert message to the DNS Log which would then provide you with the 
FQDN requested?  As of Suricata 2.0.2 "DNS TXT parsing and logging. Funded by Emerging Threats"

Cheers,
Nathan

------------------------------------------------------------------------------
Dive into the World of Parallel Programming! The Go Parallel Website, sponsored by Intel and developed in partnership 
with Slashdot Media, is your hub for all things parallel software development, from weekly thought leadership blogs 
to news, videos, case studies, tutorials and more. Take a look and join the conversation now. 
http://goparallel.sourceforge.net _______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!

------------------------------------------------------------------------------
Dive into the World of Parallel Programming! The Go Parallel Website,
sponsored by Intel and developed in partnership with Slashdot Media, is your
hub for all things parallel software development, from weekly thought
leadership blogs to news, videos, case studies, tutorials and more. Take a
look and join the conversation now. http://goparallel.sourceforge.net
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!

Attachment: smime.p7s
Description:

------------------------------------------------------------------------------
Dive into the World of Parallel Programming! The Go Parallel Website,
sponsored by Intel and developed in partnership with Slashdot Media, is your
hub for all things parallel software development, from weekly thought
leadership blogs to news, videos, case studies, tutorials and more. Take a
look and join the conversation now. http://goparallel.sourceforge.net
_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-sigs
http://www.snort.org


Please visit http://blog.snort.org for the latest news about Snort!

Current thread: