Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. we have a tool that was written in python that is meant to try and convert a Suricata 5 formatted rule into a snort rule, because we have to support both.

we have a tool that was written in python that is meant to try and convert a Suricata 5 formatted rule into a snort rule, because we have to support both.

Scheduled Pinned Locked Moved Uncategorized
5 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • da_667@infosec.exchangeD This user is from outside of this forum
    da_667@infosec.exchangeD This user is from outside of this forum
    da_667@infosec.exchange
    wrote last edited by
    #1

    we have a tool that was written in python that is meant to try and convert a Suricata 5 formatted rule into a snort rule, because we have to support both. It was called musketeer.

    It has since been unmaintained, because it was considered way too much trouble.

    I grabbed it before it was axed, made a couple of very minor changes, and renamed it janksketeer. Because I'm not a good programmer, the shit I do is really jank. Its not perfect, but it gets close enough to give me the scaffolding I need to either hang myself or make something that works.

    Link Preview Image
    viss@mastodon.socialV dio9sys@haunted.computerD invertedlina@infosec.exchangeI 3 Replies Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    • da_667@infosec.exchangeD da_667@infosec.exchange

      we have a tool that was written in python that is meant to try and convert a Suricata 5 formatted rule into a snort rule, because we have to support both. It was called musketeer.

      It has since been unmaintained, because it was considered way too much trouble.

      I grabbed it before it was axed, made a couple of very minor changes, and renamed it janksketeer. Because I'm not a good programmer, the shit I do is really jank. Its not perfect, but it gets close enough to give me the scaffolding I need to either hang myself or make something that works.

      Link Preview Image
      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.social
      wrote last edited by
      #2

      @da_667 you should s/janksketeer/janksteeter/g and see who notices 😄

      1 Reply Last reply
      0
      • da_667@infosec.exchangeD da_667@infosec.exchange

        we have a tool that was written in python that is meant to try and convert a Suricata 5 formatted rule into a snort rule, because we have to support both. It was called musketeer.

        It has since been unmaintained, because it was considered way too much trouble.

        I grabbed it before it was axed, made a couple of very minor changes, and renamed it janksketeer. Because I'm not a good programmer, the shit I do is really jank. Its not perfect, but it gets close enough to give me the scaffolding I need to either hang myself or make something that works.

        Link Preview Image
        dio9sys@haunted.computerD This user is from outside of this forum
        dio9sys@haunted.computerD This user is from outside of this forum
        dio9sys@haunted.computer
        wrote last edited by
        #3

        @da_667
        I love how the intro to suricata is "it's like snort but multi thread!"

        And then the more you look the more you realize that suricata and snort are like frisian vs dutch

        1 Reply Last reply
        0
        • da_667@infosec.exchangeD da_667@infosec.exchange

          we have a tool that was written in python that is meant to try and convert a Suricata 5 formatted rule into a snort rule, because we have to support both. It was called musketeer.

          It has since been unmaintained, because it was considered way too much trouble.

          I grabbed it before it was axed, made a couple of very minor changes, and renamed it janksketeer. Because I'm not a good programmer, the shit I do is really jank. Its not perfect, but it gets close enough to give me the scaffolding I need to either hang myself or make something that works.

          Link Preview Image
          invertedlina@infosec.exchangeI This user is from outside of this forum
          invertedlina@infosec.exchangeI This user is from outside of this forum
          invertedlina@infosec.exchange
          wrote last edited by
          #4

          @da_667 Do you happen to have a URL for the original source repo of Musketeer?

          da_667@infosec.exchangeD 1 Reply Last reply
          1
          0
          • invertedlina@infosec.exchangeI invertedlina@infosec.exchange

            @da_667 Do you happen to have a URL for the original source repo of Musketeer?

            da_667@infosec.exchangeD This user is from outside of this forum
            da_667@infosec.exchangeD This user is from outside of this forum
            da_667@infosec.exchange
            wrote last edited by
            #5

            @InvertedLina its an internal tool, but... most of its code was integrated in with IoT_Hunter to auto-convert Suri5 IoT rules in a very similar manner. https://github.com/EmergingThreats/iot-hunter

            1 Reply Last reply
            1
            0
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups