From d1eb2185ad2864078dfc8923d3dc08fc6e0f73c5 Mon Sep 17 00:00:00 2001 From: 0nnyx <54419678+0nnyx@users.noreply.github.com> Date: Tue, 31 Oct 2023 10:43:25 +0100 Subject: [PATCH] Full ET open ruleset as open-extra (#3644) * Full ET open ruleset as open-extra Follow up on #3635 to have full ET open ruleset as plugin * Update et-open-extra.xml --- .../Makefile | 4 +- .../pkg-descr | 4 +- .../suricata/metadata/rules/et-open-extra.xml | 64 ++++++++++++++++--- 3 files changed, 58 insertions(+), 14 deletions(-) diff --git a/security/intrusion-detection-content-et-open/Makefile b/security/intrusion-detection-content-et-open/Makefile index 453c803cc..e3b185e58 100644 --- a/security/intrusion-detection-content-et-open/Makefile +++ b/security/intrusion-detection-content-et-open/Makefile @@ -1,7 +1,7 @@ PLUGIN_NAME= intrusion-detection-content-et-open -PLUGIN_VERSION= 1.0.1 +PLUGIN_VERSION= 1.0.2 PLUGIN_REVISION= 1 -PLUGIN_COMMENT= IDS Proofpoint ET open ruleset complementary subset for ET Pro Telemetry edition +PLUGIN_COMMENT= IDS Proofpoint full ET open ruleset complementary subset for ET Pro Telemetry edition PLUGIN_MAINTAINER= ad@opnsense.org PLUGIN_WWW= https://rules.emergingthreats.net/ diff --git a/security/intrusion-detection-content-et-open/pkg-descr b/security/intrusion-detection-content-et-open/pkg-descr index 7065fc3ed..ef686238d 100644 --- a/security/intrusion-detection-content-et-open/pkg-descr +++ b/security/intrusion-detection-content-et-open/pkg-descr @@ -1,5 +1,5 @@ -IDS Proofpoint ET open ruleset duplicates rule files which are being -delivered empty in ET Pro Telemetry edition so both can be installed. +IDS Proofpoint ET open full ruleset to complement ET Pro Telemetry edition. +This plugin will trigger duplicate rules warnings in suricata logs when selecting the same categories for both ET open and ET Telemetry. LICENSE: https://www.proofpoint.com/us/license WWW: https://www.proofpoint.com/us/blog/threat-insight diff --git a/security/intrusion-detection-content-et-open/src/opnsense/scripts/suricata/metadata/rules/et-open-extra.xml b/security/intrusion-detection-content-et-open/src/opnsense/scripts/suricata/metadata/rules/et-open-extra.xml index ae9c0bffc..e421e8796 100644 --- a/security/intrusion-detection-content-et-open/src/opnsense/scripts/suricata/metadata/rules/et-open-extra.xml +++ b/security/intrusion-detection-content-et-open/src/opnsense/scripts/suricata/metadata/rules/et-open-extra.xml @@ -1,15 +1,59 @@ - - + + - et_open-botcc.portgrouped.rules - et_open.botcc.rules - et_open.ciarmy.rules - et_open.compromised.rules - et_open.drop.rules - et_open.dshield.rules - et_open.tor.rules - et_open.emerging-inappropriate.rules + 3coresec.rules + botcc.portgrouped.rules + botcc.rules + ciarmy.rules + compromised.rules + drop.rules + dshield.rules + emerging-activex.rules + emerging-adware_pup.rules + emerging-attack_response.rules + emerging-chat.rules + emerging-coinminer.rules + emerging-current_events.rules + emerging-deleted.rules + emerging-dns.rules + emerging-dos.rules + emerging-exploit.rules + emerging-exploit_kit.rules + emerging-ftp.rules + emerging-games.rules + emerging-hunting.rules + emerging-icmp.rules + emerging-icmp_info.rules + emerging-imap.rules + emerging-inappropriate.rules + emerging-info.rules + emerging-ja3.rules + emerging-malware.rules + emerging-misc.rules + emerging-mobile_malware.rules + emerging-netbios.rules + emerging-p2p.rules + emerging-phishing.rules + emerging-policy.rules + emerging-pop3.rules + emerging-rpc.rules + emerging-scada.rules + emerging-scan.rules + emerging-shellcode.rules + emerging-smtp.rules + emerging-snmp.rules + emerging-sql.rules + emerging-telnet.rules + emerging-tftp.rules + emerging-user_agents.rules + emerging-voip.rules + emerging-web_client.rules + emerging-web_server.rules + emerging-web_specific_apps.rules + emerging-worm.rules + tor.rules + threatview_CS_c2.rules