{"id":2038,"date":"2022-10-31T20:56:13","date_gmt":"2022-10-31T19:56:13","guid":{"rendered":"https:\/\/blog.mhasin.eu\/?p=2038"},"modified":"2022-10-31T20:56:14","modified_gmt":"2022-10-31T19:56:14","slug":"suricata-rule-list","status":"publish","type":"post","link":"https:\/\/blog.mhasin.eu\/?p=2038","title":{"rendered":"Suricata rule list"},"content":{"rendered":"\n<p>Free rule list for suricata<\/p>\n\n\n\n<p><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Emerging Threats Open Ruleset \u2013 Suricata<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/rules.emergingthreats.net\/open\/suricata-6\/emerging-all.rules.tar.gz\n<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Positive Technologies Attack Detection Team Ruleset<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/raw.githubusercontent.com\/ptresearch\/AttackDetection\/master\/pt.rules.tar.gz<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Abuse.ch SSL Blacklist Suricata Ruleset<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/sslbl.abuse.ch\/blacklist\/sslblacklist_tls_cert.tar.gz<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>abuse.ch SSLBL Snort \/ Suricata Botnet C2 IP Ruleset<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/sslbl.abuse.ch\/blacklist\/sslipblacklist.tar.gz\n<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>Abuse.ch Suricata JA3 Fingerprint Ruleset<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/sslbl.abuse.ch\/blacklist\/ja3_fingerprints.tar.gz<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>@travisbgreen Threat hunting Ruleset<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/raw.githubusercontent.com\/travisbgreen\/hunting-rules\/master\/hunting.rules<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>OISF Suricata Traffic ID Ruleset<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/openinfosecfoundation.org\/rules\/trafficid\/trafficid.rules<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>abuse.ch Feodo Tracker Botnet C2 IP<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/feodotracker.abuse.ch\/downloads\/ipblocklist.csv<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>abuse.ch SSLBL Botnet C2 IP Blacklist<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/sslbl.abuse.ch\/blacklist\/sslipblacklist.csv<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>abuse.ch ThreatFox IOCs feed<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>https:\/\/threatfox-api.abuse.ch\/api\/v1\/<\/code><\/pre>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>\\<\/p>\n<div class=\"pdf24Plugin-cp\"> \t<form name=\"pdf24Form0\" method=\"post\" action=\"https:\/\/doc2pdf.pdf24.org\/wordpress.php\" target=\"pdf24PopWin\" onsubmit=\"var pdf24Win = window.open('about:blank', 'pdf24PopWin', 'resizable=yes,scrollbars=yes,width=600,height=250,left='+(screen.width\/2-300)+',top='+(screen.height\/3-125)+''); pdf24Win.focus(); if(typeof pdf24OnCreatePDF === 'function'){void(pdf24OnCreatePDF(this,pdf24Win));}\"> \t\t<input type=\"hidden\" name=\"blogCharset\" value=\"Cw1x07UAAA==\" \/><input type=\"hidden\" name=\"blogPosts\" value=\"MwQA\" \/><input type=\"hidden\" name=\"blogUrl\" value=\"yygpKSi20tdPyslP18vNSCzOzNNLLQUA\" \/><input type=\"hidden\" name=\"blogName\" value=\"c\/LxdwcA\" \/><input type=\"hidden\" name=\"blogValueEncoding\" value=\"gzdeflate base64\" \/><input type=\"hidden\" name=\"postId_0\" value=\"MzIwtgAA\" \/><input type=\"hidden\" name=\"postTitle_0\" value=\"Cy4tykxOLElUKCrNSVXIySwuAQA=\" \/><input type=\"hidden\" name=\"postLink_0\" value=\"yygpKSi20tdPyslP18vNSCzOzNNLLdW3L7A1MjC2AAA=\" \/><input type=\"hidden\" name=\"postAuthor_0\" value=\"y00syfcwNAIA\" \/><input type=\"hidden\" name=\"postDateTime_0\" value=\"MzIwMtI1NNA1NlQwMrAyBCJjAA==\" \/><input type=\"hidden\" name=\"postContent_0\" value=\"vZbfb9owEMff+StOrdS3xKKdtmmlaNAOiakSVeFxEjLOJfEwdmRfoNpfP+c3qC8t0OYhsRP7vveR73vQG2TDiUUEmysEJR1BbCy43ErBiQ9YNuz5y69qh7kCobhzdxe7LFgpI9ZBse9iOFBy+GuDNpE6gUVqkZODWYYann1whwRXl9+v+\/1bmLfh\/ZYBy1UtYvFVaGEi9KGLxzAlytyPq8sv327LW5GzC7GWpEox1EjMeFXWQARfWbMm4EqF1TbiNkz+9QasDO3pLL6B78k4SXKLsECRaqNMItHBiIiLNTwgoSBptP\/KNw31qZB8FyaS0nyVO7TCaEJNoTAblpH18bkVKasSaPXZhjtC61ccwL6TdVQohiKF+fwRxsoLlPXRHN6Z+JxTKxXyWoutGh1WfqgnS1JuKdDScSR8j2T8CHNtLAHrSMaGfNXA\/TVMnz4BS2bt9Mgy7I6mQfg9uoGJr3C0mZWaPpriL79Zxp3ckRX2kyzfSrdKfAfSdcuANNdUdJCPts++NqtFg9IujX3ql5WH3ok2m84n3eksLI9jKWD6cCasosFJHRuHIja5jnhh+9DYhFUEVAnKqBsdhdE6Z4ImMgWHWKM9MMyJJHERmKq4XaVFZqeV4ZFjhVlMbRbhtqc5\/8DobUv7JKufkH1ljYl5gens3kGMGJ2YdPVrGZuXgGeyS95P2LbPXue59wfgzMM\/5fg\/\" \/> \t\t<a href=\"https:\/\/www.pdf24.org\" target=\"_blank\" title=\"www.pdf24.org\" rel=\"nofollow\"><img src=\"https:\/\/blog.mhasin.eu\/wp-content\/plugins\/pdf24-post-to-pdf\/img\/pdf_32x32.png\" alt=\"\" border=\"0\" height=\"32\" \/><\/a> \t\t<span class=\"pdf24Plugin-cp-space\">\u00a0\u00a0<\/span> \t\t<span class=\"pdf24Plugin-cp-text\">Send article as PDF<\/span> \t\t<span class=\"pdf24Plugin-cp-space\">\u00a0\u00a0<\/span> \t\t<input class=\"pdf24Plugin-cp-input\" style=\"margin: 0px;\" type=\"text\" name=\"sendEmailTo\" placeholder=\"Enter email address\" \/> \t\t<input class=\"pdf24Plugin-cp-submit\" style=\"margin: 0px;\" type=\"submit\" value=\"Send\" \/> \t<\/form> <\/div>","protected":false},"excerpt":{"rendered":"Free rule list for suricata Emerging Threats Open Ruleset \u2013 Suricata Positive Technologies Attack Detection Team Ruleset Abuse.ch SSL Blacklist Suricata Ruleset abuse.ch SSLBL Snort \/ Suricata Botnet C2 IP Ruleset Abuse.ch Suricata JA3 Fingerprint Ruleset @travisbgreen Threat hunting Ruleset OISF Suricata Traffic ID Ruleset abuse.ch Feodo Tracker Botnet C2 IP abuse.ch SSLBL Botnet C2 IP Blacklist abuse.ch ThreatFox IOCs feed \\ \u00a0\u00a0 Send article as PDF \u00a0\u00a0\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"arc_restricted_post":false,"footnotes":""},"categories":[10],"tags":[],"class_list":["post-2038","post","type-post","status-publish","format-standard","hentry","category-zabezpecenie"],"_links":{"self":[{"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/posts\/2038","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2038"}],"version-history":[{"count":1,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/posts\/2038\/revisions"}],"predecessor-version":[{"id":2039,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=\/wp\/v2\/posts\/2038\/revisions\/2039"}],"wp:attachment":[{"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2038"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2038"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mhasin.eu\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2038"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}