From 071f2348dd99353c7dfd7428848ea88c19038c3f Mon Sep 17 00:00:00 2001 From: Peter Manev Date: Tue, 30 Apr 2024 16:14:12 +0200 Subject: [PATCH] docker: Enable Stamus Lateral ruleset by default Disable PT research by default --- docker/scirius/bin/start-scirius.sh | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/docker/scirius/bin/start-scirius.sh b/docker/scirius/bin/start-scirius.sh index 186dfb149..d586ceba1 100644 --- a/docker/scirius/bin/start-scirius.sh +++ b/docker/scirius/bin/start-scirius.sh @@ -42,8 +42,7 @@ create_db() { python manage.py createcachetable my_cache_table python manage.py addsource "ETOpen Ruleset" https://rules.emergingthreats.net/open/suricata-5.0/emerging.rules.tar.gz http sigs - python manage.py addsource "SSLBL abuse.ch" https://sslbl.abuse.ch/blacklist/sslblacklist.rules http sig - python manage.py addsource "PT Research Ruleset" https://github.com/ptresearch/AttackDetection/raw/master/pt.rules.tar.gz http sigs + python manage.py addsource "Lateral movement ruleset" https://ti.stamus-networks.io/open/stamus-lateral-rules.tar.gz python manage.py defaultruleset "Default ruleset" python manage.py disablecategory "Default ruleset" stream-events python manage.py addsuricata suricata "Suricata" /rules "Default ruleset"