Dropping all ET COMPROMISED
-
Hello,
how can I drop all connections that are listet in the ET COMPROMISED-List?
Suricata shows alerts, I would to activate all ET COMPROMISED AND POOR REPUTATION -IPs for dropping. -
i'm using the dropsid.conf,
suricata / sid mngt / edit dropsid.conf and put inside
emerging-compromised
assign dropsid to the interface and enable sid mgnt
tick rebuild and save -
@kiokoman So I do not need to explicitly refer to every rule?
I just put the text "emerging-compromised" to dropsid.conf? -
Its pretty annoying that you cant select all and change the setting but has to click every single SID to change it.....
Makes me itch.....
-
@hebein
yes, you only need to put that inside drop.conf and all the compromised ip will be blocked
i have this inside mineemerging-ciarmy,emerging-compromised,emerging-dshield,emerging-coinminer
this way I don't need to change rules one by one