travisbgreen / hunting-rules

Suricata rules for network anomaly detection

Home Page:http://travisgreen.net

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Use "TGI HUNT" instead of "SURICATA" on some rules.

jasonish opened this issue · comments

Hi Travis,

I got really confused as to where some "SURICATA TLS on unusual port" alerts were coming from and traced them back to this rule set. Any chance you could prefix these with "TGI HUNT" as well?

Thanks.

deleted