Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:63396
This packet looks for the UUID of the NETLOGON interface being used over SMB.
1:63395
This rule looks for Netlogon packets that using the ServerPasswordSet RPC API, calling the _netr_ServerPasswordSet function.
1:63394
This rule looks for SMB WSP traffic containing a SetBindings message with and overflowed cBrow field.
1:63393
This rule looks for SMB WSP traffic containing a GetRows message with and overflowed cbReserved field.
1:63392
This rule looks for SMB WSP traffic containing a SetBindings message with and overflowed cBrow field.
1:63391
This rule looks for SMB WSP traffic containing a GetRows message with and overflowed cbReserved field.