Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:63370
This rule alerts on files associated with initial infections from IcedID botnet droppers. The indicated endpoint may be compromised.
1:63369
This rule alerts on files associated with initial infections from IcedID botnet droppers. The indicated endpoint may be compromised.
1:63368
This rule alerts on CNC install check-ins from IcedID botnet droppers. The dropper sends a survey of present anti virus engines on the endpoint before downloading the payload.
1:63367
This rule alerts on files associated with initial infections from IcedID botnet droppers. The indicated endpoint may be compromised.
1:63366
This rule alerts on files associated with initial infections from IcedID botnet droppers. The indicated endpoint may be compromised.
1:63365
This rule alerts on files associated with initial infections from IcedID botnet droppers. The indicated endpoint may be compromised.