Replies: 2 comments
-
It appears you are referencing sid 2101424:
Tuning the external side of the ruleIf you want to modify $SHELLCODE_PORTS to exclude port 7680, you can go to: Administration > Configuration > Suricata > Config > vars > port-groups > SHELLCODE_PORTS Then append a new line with the value:
Alternatively, you could also create a modify override in the Detections module. Something along the lines of (untested):
Tuning the home side of the ruleIf you were trying to tune the HOME_NET side of the rule, you would need to create a modify override in the Detections module. Something like this (untested):
Hope this information helps! |
Beta Was this translation helpful? Give feedback.
-
Thank you very much. I know I had modified the threshold on other rule time ago, but I don't know where I did take note of how I did it. In this case I have to modify the source port in order to exclude 7680 only for this rule, so I'll choose the second option. I have done these changes:
I hope this work I really thank you for your support! |
Beta Was this translation helpful? Give feedback.
-
Hello.
I'm getting many alerts "GPL SHELLCODE x86 0xEB0C NOOP" and I have seen that it's related to Microsoft Delivery Optimization and all the connections are made to port 7680, the one used by this service.
I have tried to find the way to disable this alert when destination port is 7680, but I haven't found the way.
I'll than any idea about this.
Thanks!
Beta Was this translation helpful? Give feedback.
All reactions