Rules by Product and UseCase

March 11, 2025 · View on GitHub

Vendor: Suricata

Product: Suricata

Use-Case: Lateral Movement

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
20211
Event TypeRulesModels
security-alertT1027 - Obfuscated Files or Information
A-ALERT-DL: DL Correlation rule alert on asset
A-ALERT-Correlation-Rule: Correlation rule alert on asset

T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
A-ALERT-DL: DL Correlation rule alert on asset
A-ALERT-Correlation-Rule: Correlation rule alert on asset