Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:64295
Specifically, this rule is looking for the not-legitimate SSH software version string returned by the PygmyGoat malware to open the backdoor for C2.
1:64294
This rule looks for a WASM buffer being created near triggering code of CVE-2022-1096.
1:64293
This rule looks for a WASM buffer being created near triggering code of CVE-2022-1096.
1:64292
This rule looks for command injection metacharacters present in the following parameters in HTTP requests sent to the /gsb/datetime.php endpoint on Ivanti Cloud Services Appliance web applications: TIMEZONE.
1:64291
This rule looks for command injection metacharacters present in the following parameters in HTTP requests sent to the /gsb/datetime.php endpoint on Ivanti Cloud Services Appliance web applications: TIMEZONE.
1:64290
This rule detects an attempted heap based buffer overflow against vulnerable versions of VMware vCenter Server and VMware Cloud Formation by looking for malformed boundaries in marshaled arrays sent over RPC.