OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Suricate empty rules - just a hash inside
« previous next »
  • Print
Pages: [1]

Author Topic: Suricate empty rules - just a hash inside  (Read 3224 times)

hbc

  • Hero Member
  • *****
  • Posts: 501
  • Karma: 47
    • View Profile
Suricate empty rules - just a hash inside
« on: March 20, 2019, 09:58:15 am »
Since my suricate is completely silent and I have no alerts, I took a look at the rules. Now I see that some rules are emtpy:

Code: [Select]
-rw-r-----  1 root  wheel       58 Mar 20 09:47 botcc.portgrouped.rules
-rw-r-----  1 root  wheel       58 Mar 20 09:47 botcc.rules
-rw-r-----  1 root  wheel       58 Mar 20 09:47 drop.rules
-rw-r-----  1 root  wheel       58 Mar 20 09:47 dshield.rules
-rw-r-----  1 root  wheel       58 Mar 20 09:47 tor.rules

The only content is a 58 bytes hash-string like:

#@opnsense_download_hash:8885524e8c925b9882c4602c9e517e2a

The curious thing is the tor ruleset. Before I upgraded to ET Pro telemetry edition and used the free rules, I got tor alerts. So I assume it has not been that empty before.
Logged
Intel(R) Xeon(R) Silver 4116 CPU @ 2.10GHz (24 cores)
256 GB RAM, 300GB RAID1, 3x4 10G Chelsio T540-CO-SR

ruffy91

  • Jr. Member
  • **
  • Posts: 79
  • Karma: 9
    • View Profile
Re: Suricate empty rules - just a hash inside
« Reply #1 on: March 21, 2019, 01:07:37 am »
I had the same problem using the Telemetry edition and got following answer from deciso:
"You enabled only some rulesets that have currently no active rules.

The rulesets that contain the most rules are currently the trojans (by far) and malware rules (incl. mobile)

Rulesets that are empty today are:

Botcc
Innapropriate
Pop3
Ciarmy
Compromised
Drop
Dshield

Some of them are old categories, where rules have moved to new categories and are kept for compatibility reasons.

Of course new rules can be added to currently empty sets, so including them is just fine"
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Suricate empty rules - just a hash inside
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2