ET INFO Session Traversal Utilities for NAT (STUN Binding Response)
Query · suricata
xbits:isset,ET.STUN,track ip_dst; content:"|01 01|"; depth:2; content:"|21 12 a4 42|"; fast_pattern; distance:2; within:4;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.