Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick

suricata-http-detection-rules

Sterne6
Forks0
Aktualisiert26. Juli 2026 um 16:01

Use when writing or repairing a Suricata / Snort-syntax IDS signature that must fire on one specific HTTP request shape and must stay silent on near-miss traffic — a custom exfil pattern, a C2 beacon, a data-theft POST, a suspicious header. Fires on "write a Suricata rule", "update local.rules", "alert with sid:NNNNNNN", "must not false-positive", "run suricata offline against these pcaps", or a rule graded by replaying positive and negative pcaps. Carries sticky-buffer scoping, the parameter-anchoring regex that separates true positives from lookalikes, content byte-escaping, and the offline verification loop.

Installation

Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.

SKILL.md
readonly