SURICATA
Suricata is a high-performance IDS/IPS and network monitor. Essential for intrusion detection and network security monitoring.
INSTALLATION#
# Ubuntu/Debian apt install suricata # With PPA (latest) add-apt-repository ppa:oisf/suricata-stable apt update && apt install suricata
BASIC USAGE#
IDS MODE#
suricata -c /etc/suricata/suricata.yaml -i eth0 suricata -c /etc/suricata/suricata.yaml -i eth0 -D # Daemon
PCAP MODE#
suricata -c /etc/suricata/suricata.yaml -r capture.pcap suricata -r capture.pcap -l /var/log/suricata/ # Log dir
OFFLINE PCAP#
suricata -c suricata.yaml -r file.pcap --runmode=single
OPTIONS#
-c FILE Configuration file -i INTERFACE Live capture interface -r FILE Read pcap file -s FILE Additional rules file -S FILE Rules file (exclusive) -l DIR Log directory -D Daemon mode -v Verbose -T Test configuration --af-packet AF_PACKET mode (performance)
CONFIGURATION#
MAIN CONFIG#
/etc/suricata/suricata.yaml
KEY SECTIONS#
vars: # Network variables
HOME_NET: "[192.168.0.0/16,10.0.0.0/8]"
EXTERNAL_NET: "!$HOME_NET"
HTTP_SERVERS: "$HOME_NET"
DNS_SERVERS: "$HOME_NET"
af-packet: # Capture settings
- interface: eth0
cluster-id: 99
cluster-type: cluster_flow
outputs: # Log outputs
- eve-log:
enabled: yes
filetype: regular
filename: eve.json
types:
- alert
- http
- dns
- tls
- files
rule-files: # Rules to load
- suricata.rules
- local.rules
RULE MANAGEMENT#
UPDATE RULES#
suricata-update # Update rules suricata-update list-sources # List sources suricata-update enable-source et/open # Enable source suricata-update --reload-command # Auto reload
RULE LOCATIONS#
/etc/suricata/rules/ # Default rules /var/lib/suricata/rules/ # Updated rules /etc/suricata/rules/local.rules # Custom rules
RULE SYNTAX#
BASIC STRUCTURE#
action proto src_ip src_port -> dest_ip dest_port (options)
ACTIONS#
alert Log alert pass Ignore packet drop Drop packet (IPS mode) reject Drop and send RST/ICMP rejectsrc Reject to source rejectdst Reject to destination rejectboth Reject to both
PROTOCOL#
tcp, udp, icmp, ip, http, dns, tls, ssh, ftp, smtp
EXAMPLE RULES#
# Basic alert alert tcp any any -> any 80 (msg:"HTTP Traffic"; sid:1000001; rev:1;) # Content match alert http any any -> any any (msg:"Suspicious UA"; content:"evil"; http_user_agent; sid:1000002;) # PCRE match alert http any any -> any any (msg:"SQL Injection"; pcre:"/union.*select/i"; sid:1000003;) # Flow-based alert tcp any any -> any 22 (msg:"SSH Connection"; flow:established,to_server; sid:1000004;) # Threshold alert tcp any any -> any any (msg:"Port Scan"; flags:S; threshold:type both, track by_src, count 100, seconds 60; sid:1000005;)
RULE OPTIONS#
CONTENT MATCHING#
content:"string"; # Match string content:"|4D 5A|"; # Hex match nocase; # Case insensitive depth:50; # Search depth offset:10; # Start offset distance:0; # Distance from previous within:100; # Within N bytes
HTTP KEYWORDS#
http_uri; # URI http_header; # Headers http_client_body; # POST body http_method; # GET/POST http_user_agent; # User-Agent http_host; # Host header http_cookie; # Cookies http_content_type; # Content-Type
FLOW#
flow:to_server; # To server flow:to_client; # To client flow:established; # Established flow:stateless; # Stateless
METADATA#
msg:"Description"; # Alert message sid:1000001; # Signature ID rev:1; # Revision classtype:trojan-activity; # Classification priority:1; # Priority (1=high) reference:cve,2021-44228; # Reference
THRESHOLDS#
threshold:type limit, track by_src, count 1, seconds 60; threshold:type threshold, track by_dst, count 10, seconds 60; threshold:type both, track by_src, count 5, seconds 300;
LOG FILES#
EVE.JSON#
# JSON format, one event per line # Contains: alerts, http, dns, tls, flow, etc. cat /var/log/suricata/eve.json | jq . cat eve.json | jq 'select(.event_type=="alert")' cat eve.json | jq 'select(.event_type=="http")'
FAST.LOG#
# Simple alert format # timestamp [**] [gid:sid:rev] message [**] src -> dst
STATS.LOG#
# Performance statistics
PARSING EVE.JSON#
ALL ALERTS#
cat eve.json | jq 'select(.event_type=="alert")'
SPECIFIC FIELDS#
cat eve.json | jq 'select(.event_type=="alert") | {src:.src_ip, dst:.dest_ip, msg:.alert.signature}'
HTTP EVENTS#
cat eve.json | jq 'select(.event_type=="http") | {host:.http.hostname, url:.http.url}'
DNS EVENTS#
cat eve.json | jq 'select(.event_type=="dns") | {query:.dns.rrname, type:.dns.rrtype}'
TLS EVENTS#
cat eve.json | jq 'select(.event_type=="tls") | {sni:.tls.sni, subject:.tls.subject}'
IPS MODE#
ENABLE IPS#
# In suricata.yaml nfqueue: mode: accept fail-open: yes # Run with NFQUEUE suricata -c suricata.yaml -q 0 # Iptables rules iptables -I FORWARD -j NFQUEUE --queue-num 0 iptables -I INPUT -j NFQUEUE --queue-num 0 iptables -I OUTPUT -j NFQUEUE --queue-num 0
DROP RULES#
drop tcp any any -> any 4444 (msg:"Block Meterpreter"; sid:1000010;) drop http any any -> any any (content:"malware.exe"; http_uri; sid:1000011;)
FILE EXTRACTION#
ENABLE EXTRACTION#
# In suricata.yaml file-store: enabled: yes dir: /var/log/suricata/files force-magic: yes force-hash: md5,sha256
EXTRACT RULES#
# Extract all executables alert http any any -> any any (msg:"PE Download"; fileext:"exe"; filestore; sid:1000020;)
CUSTOM RULES#
LOCAL.RULES#
# /etc/suricata/rules/local.rules
# Detect Mimikatz
alert tcp any any -> any any (msg:"Mimikatz"; content:"sekurlsa"; nocase; sid:9000001; rev:1;)
# Detect Cobalt Strike
alert http any any -> any any (msg:"Cobalt Strike"; content:"/beacon"; http_uri; sid:9000002;)
# Detect PowerShell download
alert http any any -> any any (msg:"PowerShell Download"; content:"powershell"; http_user_agent; nocase; sid:9000003;)
# Detect Base64 in URL
alert http any any -> any any (msg:"Base64 URL"; pcre:"/[A-Za-z0-9+\/]{50,}={0,2}/U"; sid:9000004;)
PERFORMANCE#
AF-PACKET MODE#
suricata -c suricata.yaml --af-packet=eth0
MULTIPLE THREADS#
# In suricata.yaml
threading:
set-cpu-affinity: yes
cpu-affinity:
- management-cpu-set:
cpu: [ 0 ]
- receive-cpu-set:
cpu: [ 1 ]
- worker-cpu-set:
cpu: [ 2-7 ]
TEST CONFIG#
suricata -T -c /etc/suricata/suricata.yaml
RELOAD RULES#
suricatasc -c reload-rules kill -USR2 $(pidof suricata)
QUICK REFERENCE#
suricata -c config.yaml -i eth0 # Live IDS suricata -c config.yaml -r file.pcap # Read pcap suricata -T -c config.yaml # Test config suricata-update # Update rules cat eve.json | jq 'select(.event_type=="alert")' # View alerts
SURICATA CHEATSHEET
===================
Source: https://cheatsheet.johlem.net
Suricata is a high-performance IDS/IPS and network monitor.
Essential for intrusion detection and network security monitoring.
INSTALLATION
------------
# Ubuntu/Debian
apt install suricata
# With PPA (latest)
add-apt-repository ppa:oisf/suricata-stable
apt update && apt install suricata
BASIC USAGE
===========
IDS MODE
--------
suricata -c /etc/suricata/suricata.yaml -i eth0
suricata -c /etc/suricata/suricata.yaml -i eth0 -D # Daemon
PCAP MODE
---------
suricata -c /etc/suricata/suricata.yaml -r capture.pcap
suricata -r capture.pcap -l /var/log/suricata/ # Log dir
OFFLINE PCAP
------------
suricata -c suricata.yaml -r file.pcap --runmode=single
OPTIONS
-------
-c FILE Configuration file
-i INTERFACE Live capture interface
-r FILE Read pcap file
-s FILE Additional rules file
-S FILE Rules file (exclusive)
-l DIR Log directory
-D Daemon mode
-v Verbose
-T Test configuration
--af-packet AF_PACKET mode (performance)
CONFIGURATION
=============
MAIN CONFIG
-----------
/etc/suricata/suricata.yaml
KEY SECTIONS
------------
vars: # Network variables
HOME_NET: "[192.168.0.0/16,10.0.0.0/8]"
EXTERNAL_NET: "!$HOME_NET"
HTTP_SERVERS: "$HOME_NET"
DNS_SERVERS: "$HOME_NET"
af-packet: # Capture settings
- interface: eth0
cluster-id: 99
cluster-type: cluster_flow
outputs: # Log outputs
- eve-log:
enabled: yes
filetype: regular
filename: eve.json
types:
- alert
- http
- dns
- tls
- files
rule-files: # Rules to load
- suricata.rules
- local.rules
RULE MANAGEMENT
===============
UPDATE RULES
------------
suricata-update # Update rules
suricata-update list-sources # List sources
suricata-update enable-source et/open # Enable source
suricata-update --reload-command # Auto reload
RULE LOCATIONS
--------------
/etc/suricata/rules/ # Default rules
/var/lib/suricata/rules/ # Updated rules
/etc/suricata/rules/local.rules # Custom rules
RULE SYNTAX
===========
BASIC STRUCTURE
---------------
action proto src_ip src_port -> dest_ip dest_port (options)
ACTIONS
-------
alert Log alert
pass Ignore packet
drop Drop packet (IPS mode)
reject Drop and send RST/ICMP
rejectsrc Reject to source
rejectdst Reject to destination
rejectboth Reject to both
PROTOCOL
--------
tcp, udp, icmp, ip, http, dns, tls, ssh, ftp, smtp
EXAMPLE RULES
-------------
# Basic alert
alert tcp any any -> any 80 (msg:"HTTP Traffic"; sid:1000001; rev:1;)
# Content match
alert http any any -> any any (msg:"Suspicious UA"; content:"evil"; http_user_agent; sid:1000002;)
# PCRE match
alert http any any -> any any (msg:"SQL Injection"; pcre:"/union.*select/i"; sid:1000003;)
# Flow-based
alert tcp any any -> any 22 (msg:"SSH Connection"; flow:established,to_server; sid:1000004;)
# Threshold
alert tcp any any -> any any (msg:"Port Scan"; flags:S; threshold:type both, track by_src, count 100, seconds 60; sid:1000005;)
RULE OPTIONS
============
CONTENT MATCHING
----------------
content:"string"; # Match string
content:"|4D 5A|"; # Hex match
nocase; # Case insensitive
depth:50; # Search depth
offset:10; # Start offset
distance:0; # Distance from previous
within:100; # Within N bytes
HTTP KEYWORDS
-------------
http_uri; # URI
http_header; # Headers
http_client_body; # POST body
http_method; # GET/POST
http_user_agent; # User-Agent
http_host; # Host header
http_cookie; # Cookies
http_content_type; # Content-Type
FLOW
----
flow:to_server; # To server
flow:to_client; # To client
flow:established; # Established
flow:stateless; # Stateless
METADATA
--------
msg:"Description"; # Alert message
sid:1000001; # Signature ID
rev:1; # Revision
classtype:trojan-activity; # Classification
priority:1; # Priority (1=high)
reference:cve,2021-44228; # Reference
THRESHOLDS
----------
threshold:type limit, track by_src, count 1, seconds 60;
threshold:type threshold, track by_dst, count 10, seconds 60;
threshold:type both, track by_src, count 5, seconds 300;
LOG FILES
=========
EVE.JSON
--------
# JSON format, one event per line
# Contains: alerts, http, dns, tls, flow, etc.
cat /var/log/suricata/eve.json | jq .
cat eve.json | jq 'select(.event_type=="alert")'
cat eve.json | jq 'select(.event_type=="http")'
FAST.LOG
--------
# Simple alert format
# timestamp [**] [gid:sid:rev] message [**] src -> dst
STATS.LOG
---------
# Performance statistics
PARSING EVE.JSON
================
ALL ALERTS
----------
cat eve.json | jq 'select(.event_type=="alert")'
SPECIFIC FIELDS
---------------
cat eve.json | jq 'select(.event_type=="alert") | {src:.src_ip, dst:.dest_ip, msg:.alert.signature}'
HTTP EVENTS
-----------
cat eve.json | jq 'select(.event_type=="http") | {host:.http.hostname, url:.http.url}'
DNS EVENTS
----------
cat eve.json | jq 'select(.event_type=="dns") | {query:.dns.rrname, type:.dns.rrtype}'
TLS EVENTS
----------
cat eve.json | jq 'select(.event_type=="tls") | {sni:.tls.sni, subject:.tls.subject}'
IPS MODE
========
ENABLE IPS
----------
# In suricata.yaml
nfqueue:
mode: accept
fail-open: yes
# Run with NFQUEUE
suricata -c suricata.yaml -q 0
# Iptables rules
iptables -I FORWARD -j NFQUEUE --queue-num 0
iptables -I INPUT -j NFQUEUE --queue-num 0
iptables -I OUTPUT -j NFQUEUE --queue-num 0
DROP RULES
----------
drop tcp any any -> any 4444 (msg:"Block Meterpreter"; sid:1000010;)
drop http any any -> any any (content:"malware.exe"; http_uri; sid:1000011;)
FILE EXTRACTION
===============
ENABLE EXTRACTION
-----------------
# In suricata.yaml
file-store:
enabled: yes
dir: /var/log/suricata/files
force-magic: yes
force-hash: md5,sha256
EXTRACT RULES
-------------
# Extract all executables
alert http any any -> any any (msg:"PE Download"; fileext:"exe"; filestore; sid:1000020;)
CUSTOM RULES
============
LOCAL.RULES
-----------
# /etc/suricata/rules/local.rules
# Detect Mimikatz
alert tcp any any -> any any (msg:"Mimikatz"; content:"sekurlsa"; nocase; sid:9000001; rev:1;)
# Detect Cobalt Strike
alert http any any -> any any (msg:"Cobalt Strike"; content:"/beacon"; http_uri; sid:9000002;)
# Detect PowerShell download
alert http any any -> any any (msg:"PowerShell Download"; content:"powershell"; http_user_agent; nocase; sid:9000003;)
# Detect Base64 in URL
alert http any any -> any any (msg:"Base64 URL"; pcre:"/[A-Za-z0-9+\/]{50,}={0,2}/U"; sid:9000004;)
PERFORMANCE
===========
AF-PACKET MODE
--------------
suricata -c suricata.yaml --af-packet=eth0
MULTIPLE THREADS
----------------
# In suricata.yaml
threading:
set-cpu-affinity: yes
cpu-affinity:
- management-cpu-set:
cpu: [ 0 ]
- receive-cpu-set:
cpu: [ 1 ]
- worker-cpu-set:
cpu: [ 2-7 ]
TEST CONFIG
-----------
suricata -T -c /etc/suricata/suricata.yaml
RELOAD RULES
------------
suricatasc -c reload-rules
kill -USR2 $(pidof suricata)
QUICK REFERENCE
---------------
suricata -c config.yaml -i eth0 # Live IDS
suricata -c config.yaml -r file.pcap # Read pcap
suricata -T -c config.yaml # Test config
suricata-update # Update rules
cat eve.json | jq 'select(.event_type=="alert")' # View alerts
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.