Skip to content

Instantly share code, notes, and snippets.

View colin-stubbs's full-sized avatar
🎯
Focusing

Colin Stubbs colin-stubbs

🎯
Focusing
View GitHub Profile
@colin-stubbs
colin-stubbs / pan_rsyslog_rb.py
Last active June 5, 2021 09:23 — forked from jtschichold/pan_rsyslog_rb.py
Generate mmnormalize rulebase for Palo Alto Networks NGFW logs
THREAT_FIELDS_5_0 = ["future_use1","receive_time","serial_number","@THREAT","log_subtype","future_use2",
"generated_time","src_ip","dest_ip","src_translated_ip","dest_translated_ip","rule","src_user",
"dest_user","app","virtual_system","src_zone","dest_zone","src_interface","dest_interface",
"log_forwarding_profile","future_use3","session_id","repeat_count","src_port","dest_port",
"src_translated_port","dest_translated_port","flags","protocol","action","misc","threat_name",
"category","severity","direction","sequence_number","action_flags","src_location","dest_location",
"future_use4","content_type"]
THREAT_FIELDS_6_0 = THREAT_FIELDS_5_0 + ["pcap_id", "url_idx", "cloud_address"]
@colin-stubbs
colin-stubbs / chromecast-ssdp.xml
Created June 9, 2019 22:42 — forked from muff1nman/chromecast-ssdp.xml
FirewallD Chromecast RHEL7/Centos7
<?xml version="1.0" encoding="utf-8"?>
<service>
<short>chromecast-ssdp</short>
<port protocol="udp" port="1900"/>
<destination ipv4="239.255.255.250/32"/>
</service>