Skip to main content
Solved

Query to search port ranges

  • July 23, 2024
  • 1 reply
  • 9 views

Mufa_shah
Forum|alt.badge.img+4

Hi all ,

Splunk logic  

| search fromPort=20 to Port= 3000

How to achieves this in yara L ?

Best answer by irfancho1994

Hi,
We can accomplish this by utilizing the UDM fields listed below in the Yara-L rule.

$network.target.port >= 20 and $network.target.port <= 3000

1 reply

Forum|alt.badge.img+2
  • New Member
  • Answer
  • July 23, 2024

Hi,
We can accomplish this by utilizing the UDM fields listed below in the Yara-L rule.

$network.target.port >= 20 and $network.target.port <= 3000