I am struggling with writing a suricata rule that could detect certain TLS errors messages like "
- ERR_SSL_VERSION_OR_CIPHER_MISMATCH
- TLSV1_Unrecognized_Name_Alert
And so on ...
Also, can Suricata/Snort, detect a fetal error, if the handshake is disabled.?!
I appreciate your advice and help,,, Thanks,,,
A suricata/snort rule.