← All cheat sheets

SURICATA

Plain-text reference · 8 KB. Read it, search it (Ctrl-F) or print it.

Suricata is a high-performance IDS/IPS and network monitor.
Essential for intrusion detection and network security monitoring.

INSTALLATION#

# Ubuntu/Debian
apt install suricata

# With PPA (latest)
add-apt-repository ppa:oisf/suricata-stable
apt update && apt install suricata

BASIC USAGE#


            

IDS MODE#

suricata -c /etc/suricata/suricata.yaml -i eth0
suricata -c /etc/suricata/suricata.yaml -i eth0 -D    # Daemon

PCAP MODE#

suricata -c /etc/suricata/suricata.yaml -r capture.pcap
suricata -r capture.pcap -l /var/log/suricata/        # Log dir

OFFLINE PCAP#

suricata -c suricata.yaml -r file.pcap --runmode=single

OPTIONS#

-c FILE             Configuration file
-i INTERFACE        Live capture interface
-r FILE             Read pcap file
-s FILE             Additional rules file
-S FILE             Rules file (exclusive)
-l DIR              Log directory
-D                  Daemon mode
-v                  Verbose
-T                  Test configuration
--af-packet         AF_PACKET mode (performance)

CONFIGURATION#


            

MAIN CONFIG#

/etc/suricata/suricata.yaml

KEY SECTIONS#

vars:               # Network variables
  HOME_NET: "[192.168.0.0/16,10.0.0.0/8]"
  EXTERNAL_NET: "!$HOME_NET"
  HTTP_SERVERS: "$HOME_NET"
  DNS_SERVERS: "$HOME_NET"

af-packet:          # Capture settings
  - interface: eth0
    cluster-id: 99
    cluster-type: cluster_flow

outputs:            # Log outputs
  - eve-log:
      enabled: yes
      filetype: regular
      filename: eve.json
      types:
        - alert
        - http
        - dns
        - tls
        - files

rule-files:         # Rules to load
  - suricata.rules
  - local.rules

RULE MANAGEMENT#


            

UPDATE RULES#

suricata-update                      # Update rules
suricata-update list-sources         # List sources
suricata-update enable-source et/open  # Enable source
suricata-update --reload-command     # Auto reload

RULE LOCATIONS#

/etc/suricata/rules/                 # Default rules
/var/lib/suricata/rules/             # Updated rules
/etc/suricata/rules/local.rules      # Custom rules

RULE SYNTAX#


            

BASIC STRUCTURE#

action proto src_ip src_port -> dest_ip dest_port (options)

ACTIONS#

alert       Log alert
pass        Ignore packet
drop        Drop packet (IPS mode)
reject      Drop and send RST/ICMP
rejectsrc   Reject to source
rejectdst   Reject to destination
rejectboth  Reject to both

PROTOCOL#

tcp, udp, icmp, ip, http, dns, tls, ssh, ftp, smtp

EXAMPLE RULES#

# Basic alert
alert tcp any any -> any 80 (msg:"HTTP Traffic"; sid:1000001; rev:1;)

# Content match
alert http any any -> any any (msg:"Suspicious UA"; content:"evil"; http_user_agent; sid:1000002;)

# PCRE match
alert http any any -> any any (msg:"SQL Injection"; pcre:"/union.*select/i"; sid:1000003;)

# Flow-based
alert tcp any any -> any 22 (msg:"SSH Connection"; flow:established,to_server; sid:1000004;)

# Threshold
alert tcp any any -> any any (msg:"Port Scan"; flags:S; threshold:type both, track by_src, count 100, seconds 60; sid:1000005;)

RULE OPTIONS#


            

CONTENT MATCHING#

content:"string";                    # Match string
content:"|4D 5A|";                   # Hex match
nocase;                              # Case insensitive
depth:50;                            # Search depth
offset:10;                           # Start offset
distance:0;                          # Distance from previous
within:100;                          # Within N bytes

HTTP KEYWORDS#

http_uri;                            # URI
http_header;                         # Headers
http_client_body;                    # POST body
http_method;                         # GET/POST
http_user_agent;                     # User-Agent
http_host;                           # Host header
http_cookie;                         # Cookies
http_content_type;                   # Content-Type

FLOW#

flow:to_server;                      # To server
flow:to_client;                      # To client
flow:established;                    # Established
flow:stateless;                      # Stateless

METADATA#

msg:"Description";                   # Alert message
sid:1000001;                         # Signature ID
rev:1;                               # Revision
classtype:trojan-activity;           # Classification
priority:1;                          # Priority (1=high)
reference:cve,2021-44228;           # Reference

THRESHOLDS#

threshold:type limit, track by_src, count 1, seconds 60;
threshold:type threshold, track by_dst, count 10, seconds 60;
threshold:type both, track by_src, count 5, seconds 300;

LOG FILES#


            

EVE.JSON#

# JSON format, one event per line
# Contains: alerts, http, dns, tls, flow, etc.

cat /var/log/suricata/eve.json | jq .
cat eve.json | jq 'select(.event_type=="alert")'
cat eve.json | jq 'select(.event_type=="http")'

FAST.LOG#

# Simple alert format
# timestamp [**] [gid:sid:rev] message [**] src -> dst

STATS.LOG#

# Performance statistics

PARSING EVE.JSON#


            

ALL ALERTS#

cat eve.json | jq 'select(.event_type=="alert")'

SPECIFIC FIELDS#

cat eve.json | jq 'select(.event_type=="alert") | {src:.src_ip, dst:.dest_ip, msg:.alert.signature}'

HTTP EVENTS#

cat eve.json | jq 'select(.event_type=="http") | {host:.http.hostname, url:.http.url}'

DNS EVENTS#

cat eve.json | jq 'select(.event_type=="dns") | {query:.dns.rrname, type:.dns.rrtype}'

TLS EVENTS#

cat eve.json | jq 'select(.event_type=="tls") | {sni:.tls.sni, subject:.tls.subject}'

IPS MODE#


            

ENABLE IPS#

# In suricata.yaml
nfqueue:
  mode: accept
  fail-open: yes

# Run with NFQUEUE
suricata -c suricata.yaml -q 0

# Iptables rules
iptables -I FORWARD -j NFQUEUE --queue-num 0
iptables -I INPUT -j NFQUEUE --queue-num 0
iptables -I OUTPUT -j NFQUEUE --queue-num 0

DROP RULES#

drop tcp any any -> any 4444 (msg:"Block Meterpreter"; sid:1000010;)
drop http any any -> any any (content:"malware.exe"; http_uri; sid:1000011;)

FILE EXTRACTION#


            

ENABLE EXTRACTION#

# In suricata.yaml
file-store:
  enabled: yes
  dir: /var/log/suricata/files
  force-magic: yes
  force-hash: md5,sha256

EXTRACT RULES#

# Extract all executables
alert http any any -> any any (msg:"PE Download"; fileext:"exe"; filestore; sid:1000020;)

CUSTOM RULES#


            

LOCAL.RULES#

# /etc/suricata/rules/local.rules

# Detect Mimikatz
alert tcp any any -> any any (msg:"Mimikatz"; content:"sekurlsa"; nocase; sid:9000001; rev:1;)

# Detect Cobalt Strike
alert http any any -> any any (msg:"Cobalt Strike"; content:"/beacon"; http_uri; sid:9000002;)

# Detect PowerShell download
alert http any any -> any any (msg:"PowerShell Download"; content:"powershell"; http_user_agent; nocase; sid:9000003;)

# Detect Base64 in URL
alert http any any -> any any (msg:"Base64 URL"; pcre:"/[A-Za-z0-9+\/]{50,}={0,2}/U"; sid:9000004;)

PERFORMANCE#


            

AF-PACKET MODE#

suricata -c suricata.yaml --af-packet=eth0

MULTIPLE THREADS#

# In suricata.yaml
threading:
  set-cpu-affinity: yes
  cpu-affinity:
    - management-cpu-set:
        cpu: [ 0 ]
    - receive-cpu-set:
        cpu: [ 1 ]
    - worker-cpu-set:
        cpu: [ 2-7 ]

TEST CONFIG#

suricata -T -c /etc/suricata/suricata.yaml

RELOAD RULES#

suricatasc -c reload-rules
kill -USR2 $(pidof suricata)

QUICK REFERENCE#

suricata -c config.yaml -i eth0      # Live IDS
suricata -c config.yaml -r file.pcap # Read pcap
suricata -T -c config.yaml           # Test config
suricata-update                      # Update rules
cat eve.json | jq 'select(.event_type=="alert")'  # View alerts

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.