Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Happy__
Collaborator

Custom Application by wireshark raws data pattern?

Hi team,

I try to create a custom signature with Wireshark raw data pattern, but it's not working.

Scenario:-I have an FTP server and I  download two files from the FTP server and capture this in Wireshark and create a signature with one file raw data. I want when next time when I download the same file from the FTP server it should be blocked by my custom signature.

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

Maybe just create a file hash IOC using the AV blade instead?
0 Kudos
Happy__
Collaborator

Yup, I know we can do with AV & IPS, but the requirement is to do with the application signature tool. 

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Wrong tool:

Signature Tool for Application and URL Filtering Administration Guide | 5 Introduction

Check Point Signature Tool lets you create Application and URL Filtering for your own or third-party applications. This tool expands your local Application and URL Filtering Database for applications and URLs that you add. Application and URL Filtering detects and enforces your policies on added signatures as with Check Point defined signatures.

For preventing downloads we use AV.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Happy__
Collaborator

In the application signature tool, there is an option that we can create a signature with raw data. So I was just trying to block a specific file with the file raw data.

 

 

0 Kudos
G_W_Albrecht
Legend Legend
Legend

That imho is a misunderstanding - APCL and URLF deal with URLs and Applications that communicate using the internet. What you want to achieve is to prevent downloading malware, a job done by AV and TE / TX. Custom Applications get defined to enable, disable or limit their internet traffic in APCL rulebase.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events