Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66538
This rule looks for DCERPC traffic where the authentication trailer length is above 0 and the number of context elements included is greater than 169.
1:66532
This rule looks for an ExceptionResponse OpenWire command containing the name of a malicious Java class that when loaded could execute arbitrary commands on the system.
1:66529
This rule looks for a specific binary signature associated with a known malicious tool targeting Microsoft Defender. Successful exploitation can lock the Defender service, causing a denial of service on the affected endpoint.
1:66528
This rule looks for a specific binary signature associated with a known malicious tool targeting Microsoft Defender. Successful exploitation can lock the Defender service, causing a denial of service on the affected endpoint.
1:66526
This rule looks for a specific sequence of bytes associated with Dirty Frag exploit payloads. Successful exploitation can grant root privileges on affected Linux systems.
1:66525
This rule looks for a specific sequence of bytes associated with Dirty Frag exploit payloads. Successful exploitation can grant root privileges on affected Linux systems.