The newest SNORTⓇ rule set is available this morning, courtesy of Cisco Talos.
Tuesday's release includes rules protecting against a multitude of malware families, including well-known threats like Emotet and Zbot. There is also new coverage for the ElectroRAT trojan, which was recently spotted in the wild trying to steal money from users' cryptocurrency wallets.
Here's a breakdown of this morning's rule release:
|Shared object rules||Modified shared object rules||New rules||Modified rules|
snort.confin this release.
Talos' rule release:
Talos has added and modified multiple rules in the file-other, malware-cnc, malware-other and server-webapp rule sets to provide coverage for emerging threats from these technologies.