Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:64132
This rule looks for command injection metacharacters in the "core.sshCommand" JSON key in requests sent to the Sourcegraph gitserver web application.
1:64131
This rule looks for specially crafted requests sent to the "/client/index.php" endpoint on Ivanti Cloud Services Appliance web application that are intended to exploit a path traversal vulnerability.
1:63856
This rule looks for XXE injection patterns included in a "sourceData.data" JSON key in requests sent to Adobe Commerce and Magento Open Source web applications.
1:63806
This rule detects a crafted HTTP request commonly used by the Grandoreiro strain of malware
1:63728
This rule alerts on network communications from the Earthworm network proxy tool. This rule may alert on any of the subcommands involved in the client-server handshake of custom TCP protocol used by Earthworm, including the establishment of a reverse socks5 tunnel from the server to the client.
1:63727
This rule alerts on network communications from the Earthworm network proxy tool. This rule may alert on any of the subcommands involved in the client-server handshake of custom TCP protocol used by Earthworm, including the establishment of a reverse socks5 tunnel from the server to the client.