Project

General

Profile

Actions

Support #2967

closed

Modbus Alerts

Added by José Monteiro almost 5 years ago. Updated almost 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Affected Versions:
Label:
Beginner

Description

Hi guys,
I've enabled Modbus in the configuration file and tested Suricata with both Modbus rules with the pcap attached, but it doesn't generate any alert.
Could you give me an example of a functioning Modbus rule?

Thank you


Files

modbus1.pcapng (2.95 KB) modbus1.pcapng José Monteiro, 05/06/2019 05:00 PM
local.rules (161 Bytes) local.rules José Monteiro, 05/06/2019 05:27 PM
Actions #1

Updated by Victor Julien almost 5 years ago

Does it work if you add '-k none' to your commandline? The pcap is full of bad checksums.

Actions #2

Updated by José Monteiro almost 5 years ago

Victor Julien wrote:

Does it work if you add '-k none' to your commandline? The pcap is full of bad checksums.

I already tried that but it didn't work also.

Actions #3

Updated by José Monteiro almost 5 years ago

Does anyone have suggestions or can give an example of a Modbus rule?

Actions #5

Updated by José Monteiro almost 5 years ago

Peter Manev wrote:

Here you can find a few examples - https://github.com/OISF/suricata/blob/master/rules/modbus-events.rules

Thank you!

Actions #6

Updated by Andreas Herz almost 5 years ago

  • Assignee set to Community Ticket
  • Target version set to Support
Actions #7

Updated by Victor Julien almost 5 years ago

  • Status changed from New to Closed
  • Assignee deleted (Community Ticket)
  • Target version deleted (Support)
Actions

Also available in: Atom PDF