Talos Rules 2023-08-24
This release adds and modifies rules in several categories.

Talos has added and modified multiple rules in the file-office, file-other and server-apache rule sets to provide coverage for emerging threats from these technologies.

For information about Snort Subscriber Rulesets available for purchase, please visit the Snort product page.

Change logs

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2092000.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)

Modified Rules:


 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091900.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)

Modified Rules:


 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091801.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)

Modified Rules:


 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091701.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)

Modified Rules:


 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091700.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)

Modified Rules:


 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091601.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)

Modified Rules:


 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091600.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)

Modified Rules:


 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091501.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)

Modified Rules:


 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091401.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)

Modified Rules:


 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091300.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)

Modified Rules:


 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091101.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)
 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 3:62308 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62314 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62303 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62311 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)
 * 3:62317 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62310 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62305 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62318 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62299 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62304 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62315 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62309 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt (file-other.rules)
 * 3:62300 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt (file-other.rules)
 * 3:62306 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt (file-other.rules)
 * 3:62307 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt (file-other.rules)
 * 3:62313 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt (file-other.rules)
 * 3:62316 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt (file-other.rules)
 * 3:62312 <-> ENABLED <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt (file-other.rules)

Modified Rules:


 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:03:16 UTC

Snort Subscriber Rules Update

Date: 2023-08-24

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2983.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:62297 <-> DISABLED <-> SERVER-APACHE Apache HTTP Server request smuggling attempt (server-apache.rules)
 * 1:62301 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62302 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:62298 <-> DISABLED <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt (malware-cnc.rules)

Modified Rules:


 * 1:51076 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:19412 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51079 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51077 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16648 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:51078 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)
 * 1:16647 <-> DISABLED <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt (file-office.rules)

2023-08-24 13:07:32 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.0.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:32 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.0.3.1.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:32 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.0.3.4.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:32 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:32 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.0.1.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:32 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.1.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.3.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.4.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.5.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.7.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.9.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.11.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.15.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.18.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.20.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.21.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.35.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.44.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt


2023-08-24 13:07:33 UTC

Snort Subscriber Rules Update

Date: 2023-08-23-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.47.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300670 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:62297 <-> SERVER-APACHE Apache HTTP Server request smuggling attempt
* 1:62298 <-> MALWARE-CNC Win.Malware.DarkGate outbound connection attempt
* 3:62299 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62300 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1820 attack attempt
* 3:62303 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62304 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62305 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62306 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1824 attack attempt
* 3:62307 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62308 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1823 attack attempt
* 3:62309 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62310 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1822 attack attempt
* 3:62311 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62312 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1821 attack attempt
* 3:62313 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62314 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1827 attack attempt
* 3:62315 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62316 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62317 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt
* 3:62318 <-> FILE-OTHER TRUFFLEHUNTER TALOS-2023-1826 attack attempt

Modified Rules:

* 1:16647 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:16648 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt
* 1:19412 <-> FILE-OFFICE Microsoft Office Excel RealTimeData record heap memory corruption attempt