Skip to content

Instantly share code, notes, and snippets.

View jasonish's full-sized avatar

Jason Ish jasonish

View GitHub Profile
@jasonish
jasonish / dnp3.json
Created May 21, 2015 17:53
dnp3 logging with payload and object data
{
"alert": {
"tx_id": 0,
"severity": 3,
"category": "",
"signature": "DNP3 Sample function code match",
"rev": 1,
"signature_id": 1,
"gid": 1,
"action": "allowed"
@jasonish
jasonish / eve-stats.json
Created June 10, 2015 18:34
EVE Stats Refactored
{
"timestamp": "2015-06-10T11:52:34.000189-0600",
"event_type": "stats",
"stats": {
// Converted to seconds.
"uptime": "1033143",
// Totals promoted to top level.
"capture": {
"kernel_packets": 292540840,
"kernel_drops": 2527
This file has been truncated, but you can view the full file.
{"timestamp":"2015-06-23T15:27:44.942830-0600","flow_id":31274912,"pcap_cnt":1883,"event_type":"dnp3","src_ip":"192.168.1.101","src_port":48566,"dest_ip":"192.168.1.2","dest_port":20000,"proto":"TCP","dnp3":{"type":"request","control":{"value":196,"dir":true,"pri":true,"fcb":false,"fcv":false,"function_code":4},"src":1,"dst":2,"transport":{"value":197,"fin":true,"fir":true,"sequence":5},"application":{"control":{"value":198,"fir":true,"fin":true,"con":false,"uns":false,"sequence":6},"function_code":1,"objects":[{"group":60,"variation":2,"prefix":0,"range":6,"data":"PAIG"},{"group":60,"variation":3,"prefix":0,"range":6,"data":"PAMG"},{"group":60,"variation":4,"prefix":0,"range":6,"data":"PAQG"}],"complete":true}}}
{"timestamp":"2015-06-23T15:27:44.942830-0600","flow_id":31274912,"pcap_cnt":1883,"event_type":"dnp3","src_ip":"192.168.1.101","src_port":48566,"dest_ip":"192.168.1.2","dest_port":20000,"proto":"TCP","dnp3":{"type":"response","control":{"value":68,"dir":false,"pri":true,"fcb":false,"fcv":false,"funct
@jasonish
jasonish / log.json
Last active September 16, 2015 19:47
{
"src_port": 47423,
"src_ip": "192.168.1.101",
"dest_port": 20000,
"dest_ip": "192.168.2.100",
"dnp3": {
"iin": {
"indicators": []
},
"application": {
@jasonish
jasonish / -
Created September 17, 2015 17:59
{
"src_port": 47423,
"src_ip": "192.168.1.101",
"dest_port": 20000,
"dest_ip": "192.168.2.100",
"dnp3": {
"iin": {
"indicators": []
},
"application": {
@jasonish
jasonish / log.json
Last active September 19, 2015 15:34
{
"src_port": 47423,
"src_ip": "192.168.1.101",
"dest_port": 20000,
"dest_ip": "192.168.2.100",
"dnp3": {
"iin": {
"indicators": []
},
"application": {
{
"dnp3": {
"response": {
"iin": {
"indicators": []
},
"application": {
"complete": true,
"objects": [
{
import angular from 'angular';
import React from "react";
function DownloadProgressBar() {
return {
restrict: "AE",
scope: {
},
link: function(scope, element) {
{"timestamp":"2015-07-14T11:45:56.361312-0600","flow_id":106790066891968,"pcap_cnt":21,"event_type":"alert","src_ip":"127.0.0.1","src_port":20000,"dest_ip":"127.0.0.1","dest_port":59602,"proto":"TCP","tx_id":3,"alert":{"action":"allowed","gid":1,"signature_id":2270004,"rev":1,"signature":"SURICATA DNP3 Unknown object","category":"","severity":3},"dnp3":{"request":{"type":"request","control":{"dir":true,"pri":true,"fcb":false,"fcv":false,"function_code":4},"src":1,"dst":10,"application":{"control":{"fir":true,"fin":true,"con":false,"uns":false,"sequence":2},"function_code":1,"objects":[{"group":60,"variation":2,"qualifier":6,"prefix_code":0,"range_code":6,"start":0,"stop":0,"count":0},{"group":60,"variation":3,"qualifier":6,"prefix_code":0,"range_code":6,"start":0,"stop":0,"count":0},{"group":60,"variation":4,"qualifier":6,"prefix_code":0,"range_code":6,"start":0,"stop":0,"count":0},{"group":60,"variation":1,"qualifier":6,"prefix_code":0,"range_code":6,"start":0,"stop":0,"count":0}],"complete":true}},"response
{
"dnp3": {
"response": {
"iin": {
"indicators": []
},
"application": {
"complete": false,
"objects": [
{