Network Blackbox

Download 39
Last updated Jan 1, 2024

nbb-suricata-rules

Get suricata rules from Quad Miners Network Blackbox.

nbb-suricata-rules [profile=PROFILE] [id=ID]
profile=PROFILE
The identifier of Network Blackbox connect profile.
id=ID
Comma separated ID values.

Output Fields

FieldTypeNameDescription
profileStringConnect profileThe identifier of Network Blackbox connect profile
signature_idIntegerSignature IDe.g. 2028828
signatureStringSignaturee.g. ET JA3 Hash - Suspected Meterpreter Reverse Shell M1 (set)
is_enabledBoolIs enabled
is_customBoolIs custom
categoryStringCategorye.g. command-and-control
src_netStringSource nete.g. $HOME_NET
src_port_rangeStringSource port rangee.g. any
dst_netStringDestination nete.g. $EXTERNAL_NET
dst_port_rangeStringDestination port rangee.g. any
appStringAppe.g. tls
actionStringActione.g. alert
referenceStringReferencee.g. cve,2010-3595
updatedDateUpdated at