SMB v1 detection in Security Onion - Bro or Snort?

319 views
Skip to first unread message

Brant Hale

unread,
Jun 27, 2017, 2:36:59 PM6/27/17
to securit...@googlegroups.com
Has anyone come up with a good way to detect SMB v1 in their environment with Security Onion?

I have been working on a Snort Rule as well as the SMB decoder in BRO, but have quite a bit of false positives based on SMB negotiation.

If someone else has solved this already please point me in the correct direction.

Thanks,

Brant 

Wes

unread,
Jun 28, 2017, 7:59:42 AM6/28/17
to security-onion
Brant,

I've not tried this personally, but have you taken a look at the following?

https://www.sans.org/reading-room/whitepapers/detection/detecting-malicious-smb-activity-bro-37472

Thanks,
Wes
Reply all
Reply to author
Forward
0 new messages