Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:64592
This rule looks for a malicious HTTP request that's related to the post-exploitation of CVE-2022-23748 and that might be exfiltrating sensitive information to threat actors related to the Stayin' Alive campaign.
1:64591
This rule looks for a malicious HTTP request that's related to the post-exploitation of CVE-2022-23748 and that might be exfiltrating sensitive information to threat actors related to the Stayin' Alive campaign.
1:64590
This rule looks for a malicious HTTP request that's related to the post-exploitation of CVE-2022-23748 and that might be exfiltrating sensitive information to threat actors related to the Stayin' Alive campaign.
1:64589
This rule specifically is looking for a known loader tool used by the Helldown ransomware group to install a backdoor on a targeted firewall.
1:64588
This rule is looking for the use of command exfiltration over vulnerable port in ES File Manager
1:64587
This rule looks for initial phishing emails sent by Koi infostealer threat actors.