[Snort-sigs] How to extract part of “content” and print in “msg” of a Snort Alert

Jeffrey Stebelton jstebelton at ...3769...
Thu Apr 18 08:35:49 EDT 2013

Does that mean in the future Snort would have the ability to include packet data in the alert? That would be a really nice feature for Snort/Sourcefire, and about the only advantage that Enterasys Dragon has over Sourcefire (I ran Dragon for over 10 years at a previous job). Including the packet data mean an intrusion analyst can make a rudimentary analysis of the alert right from his phone or pager. That’s the one feature from Dragon I really miss.

Senior Information Security Analyst
NetJets Inc.
4111 Bridgeway Avenue
Columbus, OH 43219
T: (614) 849-7281
C: (614) 364-3078
E: jstebelton at ...3769...<mailto:jstebelton at ...3769...>
NetJets® Inc. is a Berkshire Hathaway company.

From: Joel Esler [mailto:jesler at ...435...]
Sent: Monday, April 15, 2013 10:59 AM
To: Heshan Perera
Cc: snort-sigs at lists.sourceforge.net
Subject: Re: [Snort-sigs] How to extract part of “content” and print in “msg” of a Snort Alert

On Apr 15, 2013, at 9:06 AM, Heshan Perera <anthonyheshanperera at ...2420...<mailto:anthonyheshanperera at ...2420...>> wrote:

I am trying to write a Snort rule that will allow me to print the name of a file being downloaded via FTP.

The following is the rule I have so far...

alert tcp any any <> any any (content:"RETR:";msg:"A file is being downloaded.";sid:1000004;)

While this rule works, I can't figure out how to print the name of the file in the "msg" component of the alert. For example I would want the output of the alert to be something like...

"A file is being downloaded. The file name is foo.txt".

The file name is available in the content of the FTP traffic (RETR: /foo.txt)

I just cannot figure out how to extract that content and print it as a part of the message.

Any help on this would be highly appreciated.
This is not a feature that Snort currently supports in any version.

Joel Esler
Senior Research Engineer, VRT
OpenSource Community Manager

*** *** ***
This message contains information which may be confidential and privileged. Unless you are the addressee (or authorized to receive for the addressee), you may not use, copy or disclose to anyone the message or any information contained in the message. If you have received the message in error,  please advise the sender by reply e-mail and delete the message.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20130418/a1026582/attachment.html>

More information about the Snort-sigs mailing list