Content match Service Suricata_alert Date: Mon, 09 Nov 2020 04:38:55 Action: alert Host: OPN0518.myOPNsenseDomain.home.arpa Description: content match:{"timestamp":"2020-11-09T04:36:59.210662+0100","flow_id":1511934677169894,"in_iface":"em1^","event_type":"alert","src_ip":"aaa.bbb.ccc.1","src_port":67,"dest_ip":"aaa.bbb.ccc.14","dest_port":68,"proto":"UDP","alert":{"action":"blocked","gid":1,"signature_id":2022915,"rev":1,"signature":"ET INFO Web Proxy Auto Discovery Protocol WPAD DHCP 252 option Possible BadTunnel","category":"Generic Protocol Command Decode","severity":3,"metadata":{"updated_at":["2016_06_24"],"created_at":["2016_06_24"]}},"app_proto":"d
.....https://wpad.myOPNsenseDomain.home.arpa:443/wpad.dat
Enable Web Proxy Auto Discovery