Skip to content

Commit 9ba8f46

Browse files
committed
refactor(sonicwall): revamp filter and correlation rules
Rebuild the SonicWall filter so the parsed events use clear, human-readable field names and match the fields their correlation rules actually consume. Refresh the seven remaining rules so they fire on the real fields the filter emits, and drop three rules that no longer made sense as security signals for this integration. Filter changes (filters/sonicwall/sonic_wall.yml): - Emit clean origin.ip / target.ip (no port or interface glued on) - Emit protocol as tcp/udp only, keep the service hint separately - Emit action / actionResult without leftover quotes - Rescue the full text of quoted fields (message, note, category, rule, session type, VPN policy, user, uuid, action, appName, device time) so they are no longer truncated at the first space - Rename cryptic vendor tokens (m, n, sn, sess, usr, gcat, pri, dpi, ipscat, cs6, ...) to self-explanatory names like log.eventCode, log.deviceSerial, log.sessionType, log.groupCategory - Keep both syslog KV and syslog CEF supported Rules changes (rules/sonicwall/sonicwall_firewall/): - Refresh 7 rules to use the new field names - Remove 3 rules that did not belong to this integration or fired on benign traffic (Capture Client, Encrypted Threats, Zero-Day) Validated against live traffic on env 10.11.11.129.
1 parent aab1b44 commit 9ba8f46

11 files changed

Lines changed: 799 additions & 558 deletions

‎filters/sonicwall/sonic_wall.yml‎

Lines changed: 674 additions & 362 deletions
Large diffs are not rendered by default.

‎rules/sonicwall/sonicwall_firewall/anti_spyware_detection.yml‎

Lines changed: 18 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Rule version v1.0.0
1+
# Rule version v2.1.0
22

33
dataTypes:
44
- firewall-sonicwall
@@ -14,23 +14,26 @@ references:
1414
- https://www.sonicwall.com/techdocs/pdf/sonicos-6-5-4-log-events-reference-guide.pdf
1515
- https://attack.mitre.org/techniques/T1082/
1616
description: |
17-
Detects when SonicWall Anti-Spyware service identifies and blocks spyware, adware, or other potentially unwanted programs (PUPs) that may be attempting to collect sensitive information or establish persistence on the network.
17+
Detects when SonicWall Anti-Spyware service identifies and blocks spyware,
18+
adware or other potentially unwanted programs (PUPs) that may be attempting
19+
to collect sensitive information or establish persistence on the network.
1820
1921
Next Steps:
20-
- Review the detected spyware category and priority level
21-
- Investigate the source IP address for other malicious activities
22-
- Check if the blocked spyware represents a targeted attack or widespread infection
23-
- Verify that Anti-Spyware policies are properly configured and up-to-date
24-
- Consider quarantining the affected host if multiple spyware detections occur
25-
- Review network traffic patterns from the source to identify potential data exfiltration
22+
- Review the detected spyware category and priority level.
23+
- Investigate the source IP for other malicious activities.
24+
- Check whether the blocked spyware represents a targeted attack or a
25+
widespread infection.
26+
- Verify Anti-Spyware policies are properly configured and signatures
27+
up-to-date.
28+
- Consider quarantining the affected host if multiple detections cluster
29+
on the same source.
2630
where: |
27-
(exists("log.spycat") ||
28-
contains("log.message", "spyware") ||
29-
contains("log.message", "Anti-Spyware") ||
30-
contains("log.eventName", "Anti-Spyware") ||
31-
contains("log.category", "Anti-Spyware") ||
32-
(exists("log.spypri") && !equals("log.spypri", "0"))) &&
33-
(equals("action", "blocked") || equals("log.fw_action", "drop"))
31+
(
32+
oneOf("log.eventCode", ["1157", "1158", "1159"]) ||
33+
exists("log.spywareCategory") ||
34+
contains("log.message", ["spyware", "Anti-Spyware"]) ||
35+
contains("log.contentCategory", "Anti-Spyware")
36+
) && equals("actionResult", "denied")
3437
afterEvents:
3538
- indexPattern: v11-log-firewall-sonicwall-*
3639
with:
Lines changed: 16 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Rule version v1.0.0
1+
# Rule version v2.1.0
22

33
dataTypes:
44
- firewall-sonicwall
@@ -14,25 +14,30 @@ references:
1414
- https://www.sonicwall.com/support/knowledge-base/understanding-geo-ip-and-botnet-filter-diagnostics-options/200527122256150
1515
- https://attack.mitre.org/techniques/T1071/
1616
description: |
17-
Detects potential botnet command and control (C2) communication or infected host behavior identified by SonicWall's botnet filter. This includes suspicious outbound connections, HTML infection chains, or known botnet signatures.
17+
Detects potential botnet command and control (C2) communication identified
18+
by the SonicWall Botnet Filter. Includes matches against SonicWall's Botnet
19+
Filter signature codes and message text indicating known botnet endpoints.
1820
1921
Next Steps:
20-
1. Investigate the source IP for additional suspicious activity
21-
2. Check network logs for other connections from the same host
22-
3. Analyze DNS queries from the affected host
23-
4. Review endpoint logs for signs of malware infection
24-
5. Consider isolating the affected host if infection is confirmed
25-
6. Update threat intelligence feeds and security signatures
26-
7. Scan the host with updated antivirus/anti-malware tools
27-
where: (equals("log.category", "Botnet") || contains("log.message", "botnet") || contains("log.message", "infected") || contains("log.message", "C&C") || contains("log.message", "command and control") || equals("log.af_service", "botnet")) && (equals("action", "blocked") || equals("action", "dropped") || equals("log.fw_action", "drop"))
22+
1. Investigate the source IP for other suspicious behavior (DNS, beaconing).
23+
2. Check endpoint logs on the internal host for signs of infection.
24+
3. Isolate the affected host if infection is confirmed.
25+
4. Update threat intel feeds and blocklists with the observed C2 endpoint.
26+
where: |
27+
(
28+
oneOf("log.eventCode", ["1370", "1371"]) ||
29+
equals("log.appFirewallService", "botnet") ||
30+
contains("log.message", ["botnet", "Botnet", "infected", "C&C", "command and control"]) ||
31+
contains("log.contentCategory", "Botnet")
32+
) && equals("actionResult", "denied")
2833
afterEvents:
2934
- indexPattern: v11-log-firewall-sonicwall-*
3035
with:
3136
- field: origin.ip
3237
operator: filter_term
3338
value: '{{.origin.ip}}'
3439
within: 2h
35-
count: 10
40+
count: 5
3641
groupBy:
3742
- adversary.ip
3843
- target.ip
Lines changed: 23 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Rule version v1.0.0
1+
# Rule version v2.1.0
22

33
dataTypes:
44
- firewall-sonicwall
@@ -14,24 +14,37 @@ references:
1414
- https://www.sonicwall.com/support/knowledge-base/capture-atp-overview/170503785055490
1515
- https://attack.mitre.org/techniques/T1204/
1616
description: |
17-
Detects when SonicWall Capture ATP (Advanced Threat Protection) identifies a file as malicious after sandbox analysis. This indicates an attempted malware delivery or execution that was blocked by the ATP service.
17+
Detects when SonicWall Capture ATP (Advanced Threat Protection) sandboxes a
18+
file and returns a malicious verdict. Indicates an attempted malware
19+
delivery. Also covers RTDMI (Real-Time Deep Memory Inspection) verdicts
20+
which share the ATP verdict pipeline on the firewall.
1821
1922
Next Steps:
20-
1. Investigate the source IP address for additional malicious activity
21-
2. Review the file hash and name for threat intelligence correlation
22-
3. Check if the same file was delivered to other internal systems
23-
4. Verify ATP policies are properly configured and up to date
24-
5. Consider blocking the source IP at the perimeter if confirmed malicious
25-
6. Document the incident and update threat intelligence feeds
26-
where: (contains("log.msg", "Capture ATP") || contains("log.msg", "Gateway Anti-Virus") || contains("log.msg", "Sandbox") || equals("log.category", "Anti-Virus") || equals("log.af_type", "ATP")) && (contains("log.msg", "malicious") || contains("log.msg", "blocked") || contains("log.msg", "threat detected") || equals("log.result", "malicious") || equals("action", "blocked"))
23+
1. Investigate the source IP for additional malicious activity.
24+
2. Pivot on the file hash / URL captured in `log.note` against threat intel.
25+
3. Check whether the same file reached other internal systems.
26+
4. Verify ATP policies and enforce automated blocking if not already set.
27+
where: |
28+
(
29+
oneOf("log.eventCode", ["1440", "1441"]) ||
30+
equals("log.appFirewallType", "ATP") ||
31+
contains("log.message", ["Capture ATP", "Sandbox", "RTDMI"]) ||
32+
contains("log.note", ["Capture ATP", "malicious verdict", "ATP verdict"])
33+
) &&
34+
(
35+
equals("log.threatResult", "malicious") ||
36+
contains("log.message", ["malicious", "threat"]) ||
37+
contains("log.note", ["malicious", "threat"]) ||
38+
equals("actionResult", "denied")
39+
)
2740
afterEvents:
2841
- indexPattern: v11-log-firewall-sonicwall-*
2942
with:
3043
- field: origin.ip
3144
operator: filter_term
3245
value: '{{.origin.ip}}'
3346
within: 1h
34-
count: 2
47+
count: 1
3548
groupBy:
3649
- adversary.host
3750
- adversary.ip

‎rules/sonicwall/sonicwall_firewall/capture_client_threats.yml‎

Lines changed: 0 additions & 30 deletions
This file was deleted.

‎rules/sonicwall/sonicwall_firewall/encrypted_threats_detection.yml‎

Lines changed: 0 additions & 41 deletions
This file was deleted.

‎rules/sonicwall/sonicwall_firewall/gateway_antivirus_detection.yml‎

Lines changed: 14 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Rule version v1.0.0
1+
# Rule version v2.1.0
22

33
dataTypes:
44
- firewall-sonicwall
@@ -14,23 +14,22 @@ references:
1414
- https://www.sonicwall.com/techdocs/pdf/sonicos-6-5-4-log-events-reference-guide.pdf
1515
- https://attack.mitre.org/techniques/T1105/
1616
description: |
17-
Detects when SonicWall Gateway Anti-Virus (GAV) identifies and blocks malicious content. This indicates potential malware attempting to enter the network through web traffic, email attachments, or file downloads. The Gateway Anti-Virus service scans HTTP, HTTPS, FTP, and SMTP traffic in real-time to detect and prevent malware from entering the network perimeter.
17+
Detects when SonicWall Gateway Anti-Virus (GAV) identifies and blocks
18+
malicious content in HTTP/HTTPS/FTP/SMTP traffic. Signals a malware delivery
19+
attempt at the network perimeter.
1820
1921
Next Steps:
20-
1. Review the specific malware signature or threat name in the log details
21-
2. Investigate the source IP address and geolocation for suspicious patterns
22-
3. Check if the same source has attempted other malicious activities
23-
4. Verify that the anti-virus definitions are up to date
24-
5. Consider implementing additional network segmentation if internal hosts are affected
25-
6. Review firewall policies to ensure proper traffic filtering
26-
7. Escalate to incident response team if part of a coordinated attack campaign
22+
1. Review the malware name/signature carried in `log.message` / `log.note`.
23+
2. Investigate the source IP and geolocation for correlated attempts.
24+
3. Confirm the AV definitions are current on the firewall.
25+
4. Escalate to incident response if the activity is part of a broader
26+
campaign against the tenant.
2727
where: |
28-
(contains("log.gcat", "Gateway Anti-Virus") ||
29-
contains("log.message", "virus") ||
30-
contains("log.message", "malware") ||
31-
contains("log.eventName", "Anti-Virus") ||
32-
contains("log.category", "Anti-Virus")) &&
33-
equals("action", "blocked")
28+
(
29+
oneOf("log.eventCode", ["79", "608", "609", "1122"]) ||
30+
(equals("log.groupCategory", "Security Services") && contains("log.message", ["virus", "malware", "Anti-Virus"])) ||
31+
contains("log.contentCategory", "Anti-Virus")
32+
) && equals("actionResult", "denied")
3433
afterEvents:
3534
- indexPattern: v11-log-firewall-sonicwall-*
3635
with:

‎rules/sonicwall/sonicwall_firewall/intrusion_prevention_alert.yml‎

Lines changed: 19 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Rule version v1.0.0
1+
# Rule version v2.1.0
22

33
dataTypes:
44
- firewall-sonicwall
@@ -14,23 +14,27 @@ references:
1414
- https://www.sonicwall.com/techdocs/pdf/sonicos-6-5-4-log-events-reference-guide.pdf
1515
- https://attack.mitre.org/techniques/T1190/
1616
description: |
17-
Detects when SonicWall IPS identifies and blocks intrusion attempts, including buffer overflows, SQL injection, cross-site scripting, and other network-based attacks targeting vulnerabilities. This rule triggers when the SonicWall firewall's Intrusion Prevention System detects malicious traffic patterns or known attack signatures.
17+
Detects when SonicWall Intrusion Prevention System (IPS) blocks an attack
18+
matching a known signature — buffer overflow attempts, SQL injection,
19+
cross-site scripting, exploit kits, etc. Reflects the IPS Prevention Alert
20+
message family (event codes 88 / 89 / 100 / 785) as well as the descriptive
21+
`log.message`, `log.contentCategory` and `log.ipsCategory` fields.
1822
1923
Next Steps:
20-
1. Verify the blocked attack by reviewing the SonicWall logs for attack details and signatures matched
21-
2. Check if the attack was successfully blocked or if any traffic bypassed the IPS
22-
3. Investigate the source IP for additional malicious activity or patterns
23-
4. Review target systems for any signs of compromise if the attack was not fully blocked
24-
5. Update IPS signatures if new attack patterns are discovered
25-
6. Consider implementing additional network segmentation if attacks are targeting critical systems
26-
7. Review and update security policies if necessary to prevent similar attacks
24+
1. Review the matched signature and CVE (if any) in `log.message` / `log.note`.
25+
2. Confirm the block succeeded — check for follow-up connections from the
26+
same source that bypassed IPS.
27+
3. Investigate the target for compromise signs if the signature was severity
28+
high/critical.
29+
4. Update IPS profile if the target service is not supposed to expose that
30+
surface.
2731
where: |
28-
(exists("log.ipscat") ||
29-
contains("log.message", "IPS") ||
30-
contains("log.eventName", "Intrusion") ||
31-
contains("log.category", "Intrusion Prevention") ||
32-
(exists("log.ipspri") && !equals("log.ipspri", "0"))) &&
33-
(equals("action", "blocked") || equals("log.fw_action", "drop"))
32+
(
33+
oneOf("log.eventCode", ["88", "89", "100", "785"]) ||
34+
exists("log.ipsCategory") ||
35+
contains("log.message", ["IPS Detection Alert", "IPS Prevention Alert", "Intrusion"]) ||
36+
contains("log.contentCategory", "Intrusion Prevention")
37+
) && equals("actionResult", "denied")
3438
afterEvents:
3539
- indexPattern: v11-log-firewall-sonicwall-*
3640
with:
Lines changed: 17 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
# Rule version v1.0.0
1+
# Rule version v2.1.0
22

33
dataTypes:
44
- firewall-sonicwall
@@ -14,29 +14,32 @@ references:
1414
- https://www.sonicwall.com/techdocs/pdf/sonicos-6-5-4-log-events-reference-guide.pdf
1515
- https://attack.mitre.org/techniques/T1110/
1616
description: |
17-
Detects multiple failed authentication attempts to the SonicWall management interface, indicating potential brute force attacks against administrative credentials.
17+
Detects failed authentication attempts against the SonicWall management
18+
interface (GUI/CLI/API). Repeated failures from a single source IP suggest
19+
a brute-force or credential-stuffing attack targeting admin credentials.
1820
1921
Next Steps:
20-
1. Investigate the source IP address attempting authentication
21-
2. Check if the source IP is from an authorized management network
22-
3. Review for successful logins from the same IP after failures
23-
4. Consider blocking the source IP on the management interface
24-
5. Restrict management access to specific IP addresses
25-
6. Enable account lockout and two-factor authentication
22+
1. Investigate the source IP — geolocation, reputation, previous activity.
23+
2. Confirm the source is NOT from an authorized management network.
24+
3. Search for a successful admin login from the same IP AFTER the failures
25+
(indicator of a successful brute force).
26+
4. Restrict management access to specific IP ranges and enforce MFA.
2627
where: |
27-
((contains("log.message", ["admin", "management", "login"]) &&
28-
contains("log.message", ["fail", "denied", "invalid", "incorrect"])) ||
29-
contains("log.eventName", ["Administrator login failed", "Login failure"]) ||
30-
contains("log.category", "Authentication Access")) &&
31-
exists("origin.ip")
28+
(
29+
oneOf("log.eventCode", ["29", "32", "33", "1246"]) ||
30+
(
31+
contains("log.message", ["admin", "administrator", "login", "management"]) &&
32+
contains("log.message", ["failed", "fail", "denied", "invalid", "incorrect"])
33+
)
34+
) && exists("origin.ip")
3235
afterEvents:
3336
- indexPattern: v11-log-firewall-sonicwall-*
3437
with:
3538
- field: origin.ip
3639
operator: filter_term
3740
value: '{{.origin.ip}}'
3841
within: 15m
39-
count: 10
42+
count: 5
4043
groupBy:
4144
- adversary.ip
4245
- adversary.user

0 commit comments

Comments
 (0)