11 March 2021

Suricata check config

list all effective config:

 suricata --dump-config



check rules in rules files:

suricata -T -S "rules/malware.rules"




notes on flow/flowbits:

https://suricata.readthedocs.io/en/latest/rules/flow-keywords.html