Showing posts with label community. Show all posts
Showing posts with label community. Show all posts

Thursday, June 9, 2022

Changes to the community rule release schedule

By Jon Munshaw. 

As of this week, we are changing the cadence for releases for the Snort community rule set. 

Previously, the community rules were released every day at 11:40 a.m. ET, even if there are no rule changes. Now, the rule set will align with our normal open-source build and release schedule. This is usually every Tuesday and Thursday, though this may change based on public holidays and ad hoc releases for certain vulnerabilities or malware families. 

We apologize for any disruptions this may cause.  

Community rules are a set of rules that members of our open-source community or Snort integrators have submitted. These rules are freely available to all Snort users and are governed by the GPLv2. Anyone can submit a community rule using the Snort Rules mailer here

Community rules are available for anyone to download here without registration and are free of charge without any Rule Set License restrictions.  

Wednesday, September 1, 2021

Snort OpenAppID Detectors have been updated

SNORTⓇ released a new update today for its OpenAppID Detector content.

This release — build 346 — includes:
  • 3,066 detectors. 
  • Additional detectors from the open-source community. For more details on which contributions were included, we have added them to the "Authors" file in this package.
The release is available now on our Downloads page. We look forward to users downloading and using the new features. If you have any feedback,  please share it with the OpenAppID mailing list.

The OpenAppID package is also compatible with our most recent Snort 3 releases.

Tuesday, July 27, 2021

Join Snort on Discord








We are excited to have SNORT® on Discord now

Our Discord channel is the perfect place to ask questions to the community, check out new rule releases and just hang out with other members of the community.

All you have to do is click on this link and you'll be added to the community (if you've downloaded Discord).

Wednesday, May 12, 2021

Snort OpenAppID Detectors have been updated

SNORTⓇ released a new update today for its Snort OpenAppID Detector content.

This release — build 342 — includes:
  • 2,971 detectors. 
  • Additional detectors from the open-source community. For more details on which contributions were included, we have added them to the "Authors" file in this package.
The release is available now on our Downloads page. We look forward to users downloading and using the new features. If you have any feedback,  please share with the OpenAppID mailing list.

The OpenAppID package is also compatible with our Snort 3.x release.

Thursday, February 11, 2021

Snort OpenAppID Detectors have been updated

 SNORTⓇ released a new update today for the Snort OpenAppID Detector content.

This release — build 341 — includes:
  • A total of 2,926 detectors. 
  • Additional detectors from the open-source community. For more details on which contributions were included, we have added them to the "Authors" file in this package.
The release is available now on our downloads page. We look forward to users downloading and using the new features of 2.9.17.0's OpenAppID preprocessor and sharing your experiences with the community.

The OpenAppID package is also compatible with our Snort 3.x release.

The OpenAppID community has a mailing list specifically dedicated to the exchange and discussion of detector content. Please visit the mailing lists page to sign up.

Wednesday, November 18, 2020

Snort OpenAppID Detectors have been updated

SNORTⓇ released a new update today for the Snort OpenAppID Detector content.

This release — build 339 — includes:
  • A total of 2,927 detectors. 
  • Additional detectors from the open-source community. For more details on which contributions were included, we have added them to the "Authors" file in this package.
The release is available now on our downloads page. We look forward to users downloading and using the new features of 2.9.16.1's OpenAppID preprocessor and sharing your experiences with the community.

The OpenAppID package is also compatible with our Snort 3.0 release.

The OpenAppID community has a mailing list specifically dedicated to the exchange and discussion of detector content. Please visit the mailing lists page to sign up.

Thursday, October 15, 2020

Better application logging with Snort3



By Costas Kleopa.


With the introduction of OpenAppID in SNORT®, we started to provide application-based information for our network flows. A user could enable the AppID preprocessor, load our Open Detector Package (snort-openappid.tgz) from the Snort Downloads page and — with the integration of any third-party tools — we could provide a deeper graphical representation of what’s running over a network. (See the blog here for an example showing Integration with Splunk.) The app_stats logging configuration allowed us to report some basic statistics on what type of traffic we can see per application and the overall traffic size we see during a specific recurring time interval.  


We also provide additional AppID-based control via the IPS rules. These IPS rules were allowing us to block/alert the actual application and ultimately log this information on a per-packet basis. The combination of alert/logging in IPS rules partially met a use case that the field has been asking for, which is logging the application per connection. Unfortunately, this was not the best solution, since this was causing us to report this information per packet and could cause some performance issues with a lot of duplicate data. 

Monday, August 24, 2020

Snort OpenAppID Detectors have been updated

SNORTⓇ released a new update today for the Snort OpenAppID Detector content.

This release — build 337 — includes:
  • A total of 2,917 detectors. 
  • Additional detectors from the open-source community. For more details on which contributions were included, we have added them to the AUTHORS file in this package.
The release is available now on our downloads page. We look forward to users downloading and using the new features of 2.9.16.1's OpenAppID preprocessor and sharing your experiences with the community.

The OpenAppID package is also compatible with our Snort 3.0 release.

The OpenAppID community has a mailing list specifically dedicated to the exchange and discussion of detector content. Please visit the mailing lists page to sign up.

Thursday, November 14, 2019

Snort OpenAppID Detectors have been updated

SNORTⓇ released a new update today for the Snort OpenAppID Detector content.

This release — build 329 — includes:
  • A total of 2,890 detectors. 
  • It also includes some additional detectors that came in from the open-source community. For more details on which contributions were included, we have added them to the AUTHORS file in this package.
Available now for download from our downloads page, we look forward to you downloading and using the new features of 2.9.15.0's OpenAppID preprocessor and sharing your experiences with the community.

The OpenAppID package is also compatible with our Snort 3.0 release.

The OpenAppID community has a mailing list specifically dedicated to the exchange and discussion of detector content. Please visit the mailing lists page to sign up.

Tuesday, September 17, 2019

Snort OpenAppID Detectors have been updated

An update has been released today for the Snort OpenAppID Detector content.

This release, build 326, includes:
  • A total of 2,880 detectors. 
  • It also includes some additional detectors that came in from the open source community. For more details on which contributions were included, we have added them in the AUTHORS file in this package.
Available now for download from our downloads page, we look forward to you downloading and using the new features of 2.9.14.1's OpenAppID preprocessor and sharing your experiences with the community.

The OpenAppID package is also compatible with our Snort 3.0 release.

The OpenAppID community has a mailing list specifically dedicated to the exchange and discussion of detector content.  Please visit the mailing lists page to sign up.

Wednesday, April 17, 2019

Snort blog comments are now disabled

As the topic of the post says, blog comments on this blog are now disabled.

Why?

99% (percentage is entirely made up, but most likely more accurate than non-accurate) of all the comments were spam.  The majority of my time moderating the comments on the blog was spent mashing the "Spam" button.

Every once in awhile a real comment would appear on the blog, and 99% of those comments were answered by me answering with "Go to the mailing lists".

So, in the interest of my sanity, and the fact that the mailing lists provide a better answer and conversational interaction than a blog comment ever could, I've disabled blog comments.

Please direct your questions to the Snort mailing lists: https://www.snort.org/community

Thanks all!

Friday, April 5, 2019

Update to Snort OpenAppID detectors

We recently released an update to the Snort OpenAppID Detector content.

This release, build 319, includes a total of 2,836 detectors, as well as some additional detectors that came in from the open-source community. For more details on which contributions we included, we have added them to the "Authors" file in this package.f

The update is available for download now from our downloads page. We look forward to you downloading and using the new features of 2.9.12.0's OpenAppID preprocessor and sharing your experiences with the community.

The OpenAppID community has a mailing list specifically dedicated to the exchange and discussion of detector content.  Please visit the mailing lists page to sign up.

Friday, January 11, 2019

Snort OpenAppID Detectors have been updated

An update has been released today for the Snort OpenAppID Detector content. This release, build 308, includes:
  • A total of 2,833 detectors. 
  • It also includes some additional detectors that came in from the open source community. For more details on which contributions were included, we have added them in the AUTHORS file in this package.
Available now for download from our downloads page, we look forward to you downloading and using the new features of 2.9.12.0's OpenAppID preprocessor and sharing your experiences with the community.

The OpenAppID community has a mailing list specifically dedicated to the exchange and discussion of detector content.  Please visit the mailing lists page to sign up.

Monday, January 7, 2019

The return of the Snort community rule contest

After a brief hiatus, the SNORTⓇ community rule contest is back. Here at Snort, we always strive to improve our detection. And we appreciate it when our community joins in the fight against the bad guys.

We are reviving the contest as a way to thank those of you who regularly engage with us and submit rules that we wind up deploying. While the old contest ran on a monthly basis, this time around, we will be giving out prizes on a quarterly basis.

Each quarter, we will give out a Snort-themed prize — whether it be a calendar, T-shirt, mug or something else exciting — to the community member who submits the most rules to us during that time. Be sure to follow us on Twitter each quarter to see who the winner is. If you are the winner, be sure to keep an eye out in your inbox for details on how to claim your prize.

We are accepting signatures into the community ruleset (GPLv2 licensed) via the Snort-Sigs mailing list, which anyone may join here. If you’d like to submit to the Snort ruleset please include your rule and research behind it (pcap, ASCII dump, references, etc.).

When we receive a signature, we will follow our standard internal procedures (which involves heavy QA of the signature, testing, optimization for performance, and perhaps sending the rule out to our internal and external testing groups).

You may reference the Snort Users Manual for general rules questions, as well as of course discussing it among fellow Snort rule writers in the aforementioned mailing list.

The rules will be released in the Snort rule set and are available to our customers and the Snort community as a whole via our normal community rule distribution process, published daily, with full attribution given to the author.

As always, false positive reports belong here after logging in.

The highest submitter for accepted rules for each quarter will receive some Snort goodies. Keep in mind that we must accept the rules for them to be counted toward your total for the quarter. For example, if you write a rule for an ICMP response on the network, we are not going to accept it.

We thank the community in advance for rule submissions, as well as continued submission of false positive reports.

Tuesday, October 23, 2018

Snort rule update for Oct. 23, 2018

Just released:
Snort Subscriber Rule Set Update for Oct. 23, 2018

Cisco Talos welcomes the newest SNORTⓇ rule release. In this release, we introduced 11 new rules, four of which are shared object. There are also two modified rules, none of which are shared object rules.

Thursday, October 4, 2018

Snort rule blog post for Oct. 4, 2018

Just released:
Snort Subscriber Rule Set Update for Oct. 4, 2018

Cisco Talos just released the newest SNORTⓇ rule set. In this release, we introduced 46 new rules, three of which are shared object rules. There are also 22 modified rules.

This release covers additional Adobe Acrobat and Reader vulnerabilities that were disclosed on Oct. 1. The Snort rule release from earlier this week also addressed some of these bugs. Talos specifically discovered CVE-2018-12852, a remote code execution flaw in Acrobat that could allow an attacker to manipulate the victim machine's memory and execute code.

There were no changes made to the snort.conf in this release.

Talos's rule release:
Talos has added and modified multiple rules in the deleted, file-image, file-multimedia, file-other, file-pdf, malware-cnc, server-mail and server-webapp rule sets to provide coverage for emerging threats from these technologies.
In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 U.S. a year for personal users. Be sure and see our business pricing as well at https://snort.org/products#rule_subscriptions. Make sure and stay up to date to catch the most emerging threats.

Tuesday, October 2, 2018

Snort rule update for Oct. 2, 2018


Just released:
Snort Subscriber Rule Set Update for Oct. 2, 2018

Today, Cisco Talos released the newest SNORTⓇ rule update. In this release, we introduced 79 new rules, none of which are shared object rules. There are also 22 modified rules.

This release mainly covers more than 80 vulnerabilities that Adobe recently disclosed in its Acrobat and Reader products. An attacker could exploit these bugs to execute code in the context of the current user.

Thursday, September 27, 2018

Snort rule update for Sept. 27, 2018

Just released:
Snort Subscriber Rule Set Update for Sept. 27, 2018

Today, Cisco Talos released the newest rule update for SNORTⓇ. In this release, we introduced 27 new rules, of which six are shared object rules. There are no modified rules in this update.

This release provides coverage for multiple important vulnerabilities in Cisco IOS XE, as well as a new malware variant from the OilRig APT that has been spotted targeting governments in the Middle East. Our rules block any outbound connections that the malware tries to make.

Tuesday, September 18, 2018

Snort rule update for Sept. 18, 2018


Just released:
Snort Subscriber Rule Set Update for Sept. 18, 2018

The newest Snort rule update rule release was released this morning by Cisco Talos. In this release, we introduced 37 new rules, three of which are shared object rules. There are also 2,155 modified rules, none of which are shared object rules.

This release provides coverage for multiple bugs in Adobe ColdFusion and Flash Player, as well as the malware families njrat and DownloadGuide.

There were no changes made to the snort.conf in this release.

Talos's rule release:
Talos has added and modified multiple rules in the exploit-kit, file-flash, file-identify, file-image, file-java, file-multimedia, file-office, file-other, file-pdf, indicator-compromise, malware-backdoor, malware-cnc, malware-other, netbios, os-linux, os-mobile, os-other, os-windows, policy-other, protocol-dns, protocol-ftp, protocol-icmp, protocol-imap, protocol-rpc, protocol-scada, protocol-services, protocol-snmp, protocol-tftp, protocol-voip, pua-adware, pua-toolbars, server-apache, server-iis, server-mail, server-mssql, server-mysql, server-oracle, server-other and sql rule sets to provide coverage for emerging threats from these technologies.
In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 U.S. a year for personal users. Be sure and see our business pricing as well at https://snort.org/products#rule_subscriptions. Make sure and stay up to date to catch the most emerging threats.

Thursday, September 13, 2018

Snort rule update for Sept. 13, 2018

Just released:
Snort Subscriber Rule Set Update for Sept. 13, 2018

Today, we welcome the newest rule release from Talos. In this release, we introduced 48 new rules, of six which are shared object rules. There are also 501 modified rules, none of which are shared object rules.

This update provides coverage for CVE-2018-8475, a coding deficiency in Microsoft Windows that could allow an attacker to execute code on the victim machine.

There are also rules addressing multiple vulnerabilities in Adobe Flash Player and Adobe ColdFusion, including two critical bugs.

There were no changes made to the snort.conf in this release.

Talos's rule release:
Talos also has added and modified multiple rules in the app-detect, browser-chrome, browser-firefox, browser-ie, browser-other, browser-plugins, browser-webkit, deleted, file-flash, file-image, file-other, file-pdf, malware-cnc and server-webapp rule sets to provide coverage for emerging threats from these technologies.
In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 U.S. a year for personal users. Be sure and see our business pricing as well at https://snort.org/products#rule_subscriptions. Make sure and stay up to date to catch the most emerging threats.