<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Event analysis - regular expressions in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/event-analysis-regular-expressions/m-p/2876950#M44103</link>
    <description>&lt;P&gt;Hello - I am trying to locate additional information regarding sid 32621.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" id="section_tab.991f88d20a00064127420bc37824d385" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;&lt;SPAN id="section-991f88d20a00064127420bc37824d385" data-header-only="false" class="section "&gt;&lt;SPAN id="activity_301f3bd52b02560090e482e3e4da1599.0_div" class="activity_update_group" style="display: block;" name="activity_0_div"&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"MALWARE-CNC Win.Trojan.Regin outbound connection"; flow:to_server,established; content:" TW="; fast_pattern:only; content:" TW="; http_cookie; metadata:impact_flag red, policy security-ips drop, service http; reference:url,&lt;A href="http://www.virustotal.com/en/file/c0cf8e008fbfa0cb2c61d968057b4a077d62f64d7320769982d28107db370513/analysis/" target="_blank"&gt;www.virustotal.com/en/file/c0cf8e008fbfa0cb2c61d968057b4a077d62f64d7320769982d28107db370513/analysis/&lt;/A&gt;; classtype:trojan-activity; sid:32621; rev:3; ) &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;I understand that once the content is matched on "TW=" the pcre is called to perform regex matching.&amp;nbsp; How do I determine the contents of this specific pcre?&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;I understand that TAC could provide a more in-depth analysis if needed.&amp;nbsp; However any additional insight I can gain into why this fired would help tremendously in future event analysis as well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 13:34:44 GMT</pubDate>
    <dc:creator>C. Leg</dc:creator>
    <dc:date>2019-03-10T13:34:44Z</dc:date>
    <item>
      <title>Event analysis - regular expressions</title>
      <link>https://community.cisco.com/t5/network-security/event-analysis-regular-expressions/m-p/2876950#M44103</link>
      <description>&lt;P&gt;Hello - I am trying to locate additional information regarding sid 32621.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" id="section_tab.991f88d20a00064127420bc37824d385" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;&lt;SPAN id="section-991f88d20a00064127420bc37824d385" data-header-only="false" class="section "&gt;&lt;SPAN id="activity_301f3bd52b02560090e482e3e4da1599.0_div" class="activity_update_group" style="display: block;" name="activity_0_div"&gt;alert tcp $HOME_NET any -&amp;gt; $EXTERNAL_NET $HTTP_PORTS (msg:"MALWARE-CNC Win.Trojan.Regin outbound connection"; flow:to_server,established; content:" TW="; fast_pattern:only; content:" TW="; http_cookie; metadata:impact_flag red, policy security-ips drop, service http; reference:url,&lt;A href="http://www.virustotal.com/en/file/c0cf8e008fbfa0cb2c61d968057b4a077d62f64d7320769982d28107db370513/analysis/" target="_blank"&gt;www.virustotal.com/en/file/c0cf8e008fbfa0cb2c61d968057b4a077d62f64d7320769982d28107db370513/analysis/&lt;/A&gt;; classtype:trojan-activity; sid:32621; rev:3; ) &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;I understand that once the content is matched on "TW=" the pcre is called to perform regex matching.&amp;nbsp; How do I determine the contents of this specific pcre?&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;I understand that TAC could provide a more in-depth analysis if needed.&amp;nbsp; However any additional insight I can gain into why this fired would help tremendously in future event analysis as well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="display: block;" data-header-only="false" class="tabs2_section tabs2_section_1 tabs2_section1 tab_section" tab_caption="Notes" data-section-id="991f88d20a00064127420bc37824d385" tab_caption_raw="Notes"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-analysis-regular-expressions/m-p/2876950#M44103</guid>
      <dc:creator>C. Leg</dc:creator>
      <dc:date>2019-03-10T13:34:44Z</dc:date>
    </item>
  </channel>
</rss>

