Skip to content

Instantly share code, notes, and snippets.

@ackatz
ackatz / dropsid.conf
Created December 30, 2020 16:17
pfSense Suricata Inline IPS Dropsid.conf
emerging-3coresec,emerging-activex,emerging-adware_pup,emerging-attack_response,emerging-botcc.portgrouped,emerging-botcc,emerging-chat,emerging-ciarmy,emerging-coinminer,emerging-compromised,emerging-current_events,emerging-deleted,emerging-dns,emerging-dos, emerging-drop,emerging-dshield, emerging-exploit,emerging-exploit_kit,emerging-ftp,emerging-games,emerging-hunting,emerging-icmp,emerging-icmp_info,emerging-imap,emerging-inappropriate,emerging-info,emerging-ja3,emerging-malware,emerging-misc,emerging-mobile_malware,emerging-netbios,emerging-p2p,emerging-phishing,emerging-policy,emerging-pop3,emerging-rpc,emerging-scada,emerging-scan,emerging-shellcode,emerging-smtp,emerging-snmp,emerging-sql,emerging-telnet,emerging-tftp,emerging-tor,emerging-user_agents,emerging-voip,emerging-web_client,emerging-web_server,emerging-web_specific_apps,emerging-worm
@ackatz
ackatz / dropsid.conf
Last active December 30, 2020 16:16
pfSense Snort Inline IPS Dropsid.conf
emerging-activex,snort_app-detect,snort_browser-chrome.so,openappid-ads,emerging-attack_response,snort_attack-responses,snort_browser-ie.so,openappid-browser_plugin,emerging-botcc.portgrouped,snort_backdoor,snort_browser-other.so,openappid-bussiness_applications,emerging-botcc,snort_bad-traffic,snort_browser-webkit.so,openappid-collaboration,emerging-chat,snort_blacklist,snort_exploit-kit.so,openappid-database,emerging-ciarmy,snort_botnet-cnc,snort_file-executable.so,openappid-file_storage,emerging-compromised,snort_browser-chrome,snort_file-flash.so,openappid-file_transfer,emerging-current_events,snort_browser-firefox,snort_file-image.so,openappid-games,emerging-deleted,snort_browser-ie,snort_file-java.so,openappid-hacktools,emerging-dns,snort_browser-other,snort_file-multimedia.so,openappid-mail,emerging-dos,snort_browser-plugins,snort_file-office.so,openappid-messaging,emerging-drop,snort_browser-webkit,snort_file-other.so ,openappid-mobile,emerging-dshield,snort_chat,snort_file-pdf.so,openappid-network_ma