Skip to main content
Run any Skill in Manus
with one click

suricata-http-detection-rules

Stars6
Forks0
UpdatedJuly 26, 2026 at 16:01

Use when writing or repairing a Suricata / Snort-syntax IDS signature that must fire on one specific HTTP request shape and must stay silent on near-miss traffic — a custom exfil pattern, a C2 beacon, a data-theft POST, a suspicious header. Fires on "write a Suricata rule", "update local.rules", "alert with sid:NNNNNNN", "must not false-positive", "run suricata offline against these pcaps", or a rule graded by replaying positive and negative pcaps. Carries sticky-buffer scoping, the parameter-anchoring regex that separates true positives from lookalikes, content byte-escaping, and the offline verification loop.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly