Showing posts with label configurations. Show all posts
Showing posts with label configurations. Show all posts

Monday, March 5, 2018

Talos Snort configuration files have been updated

I just posted the updated Talos Snort configuration files to the Documentation page on Snort.org.

Keeping in mind that the snort.conf file that ships with the Snort tarball is only up to date, when that tarball ships.  In order to make sure you stay updated to the latest recommended configurations, its recommended that the snort.conf is also kept current.

Talos keeps the tedious nature of updating the snort.conf in mind, and we try to minimize the amount of changes done.

Wednesday, June 29, 2016

Snort.conf examples have been posted!

When changes are made to the Snort.conf, we update our example configuration page on Snort.org in order to provide the latest updates to the community.  The Snort.conf that ships with the Snort tarball is only updated upon version release.

Please take a look at the latest updates to the Snort.conf on our website, download and use these, as appropriate.

Friday, June 5, 2015

Snort's default configuration files have been updated!

As always, on the website we keep the master record of the snort.conf file for each version of Snort available, and keep this up to date with every supported release of Snort.

I know I'm a bit behind in moving these between servers, but here they are.  Especially useful for Windows users, as the snort.conf in packaged version of Windows on the website is a bit behind.  (Thanks Michael Steele for pointing that out)

Download the default snort.conf files on the website.

Thanks!

Monday, August 18, 2014

Snort Subscriber Ruleset: Re-categorization of the Shared Object Rules

In 2012, the VRT (now Talos) performed a massive restructuring of the plaintext ruleset from the old category structure to a new category structure.  Since then we've received overwhelmingly positive feedback about them, so we will continue the effort by moving the Shared Object Rules into a similar category structure.

With tomorrow's rule release we will be introducing the following Shared Object Rule Categories:

browser-ie.rules
browser-other.rules
browser-plugins.rules
exploit-kit.rules
file-executable.rules
file-flash.rules
file-image.rules
file-java.rules
file-multimedia.rules
file-office.rules
file-other.rules
file-pdf.rules
indicator-shellcode.rules
malware-cnc.rules
malware-other.rules
netbios.rules
os-linux.rules
os-other.rules
os-windows.rules
policy-social.rules
protocol-dns.rules
protocol-icmp.rules
protocol-nntp.rules
protocol-other.rules
protocol-snmp.rules
protocol-voip.rules
pua-p2p.rules
server-apache.rules
server-iis.rules
server-mail.rules
server-mysql.rules
server-oracle.rules
server-other.rules
server-webapp.rules

The example snort.conf's have been updated, and can be downloaded here: https://www.snort.org/configurations, and will being shipping in the Snort Subscriber Rule Set Registered and Subscriber packages immediately.

If you are using PulledPork to manage your ruleset, (as you should be), in the default mode, you shouldn't have to do anything, as all the rule files are merged into one file by default.

Any questions, please do not hesitate to contact us via the Snort mailing lists.

Tuesday, February 25, 2014

Snort 2.9.7.0 Alpha release now available!

Just posted to Snort.org, Snort 2.9.7.0 Alpha. We have some exciting things in store here that we've been looking forward to releasing. Please see the below notes for more details!

We also put out a couple of press releases this morning about OpenAppID.  Take a look:
http://finance.yahoo.com/news/cisco-security-introduces-open-source-130000271.html

Our founder Marty also wrote a blog post over on the Cisco blog:
http://blogs.cisco.com/security/cisco-announces-openappid-the-next-open-source-game-changer-in-cybersecurity/

Follow the @Snort account on Twitter to stay current with our releases!

2014-02-25 - Snort 2.9.7.0 alpha
[*] New additions
* Application Identification Preprocessor, when used in conjunction with
open app ID detector content, that will identify application protocol,
client, server, and web applications and include the info in Snort alert
data. In addition, a new rule option keyword 'appid' that can be used
to constrain Snort rules based on one or more applications that are identified
for the connection. See README.appid for details. Please report issues
or ask questions via a new mailing list: snort-openappid@sourceforge.net.

* A new protected_content rule option that is used to match against a content
that is hashed. It can be used to obscure the full context of the rule from
the administrator.

* Protocol Aware Flushing (PAF) improvements for SMTP, POP, and IMAP to
more accurately process different portions of email messages and file
attachments.

[*] Improvements
* Update active response to allow for responses of 1500+ bytes that span
multiple TCP packets.

* Check limits of multiple configurations to not exceed a maximum ID of 4095.

* Updated the error output of byte_test, byte_jump, byte_extract to
including details on offending options for a given rule.

* Update build and install scripts to install preprocessor and engine libraries
into user specified libdir.

Get Snort 2.9.7.0 Alpha here! https://www.snort.org/downloads

Thursday, December 5, 2013

Sourcefire VRT Certified Snort Rules Update for 12/05/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 12/05/2013

We welcome the introduction of the newest rule release from the VRT. In this release we introduced 8 new rules and made modifications to 38 additional rules.

There was one change made to the snort.conf in this release:

Port 9111 was added to HTTP_PORTS, http_inspect, and stream5 both.

The Snort.confs on the example page have been updated:
https://www.snort.org/configurations

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

Avery Tarasov:
28539
28809
28810
28814
28815

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, browser-ie, exploit-kit, file-flash, file-image, file-multimedia, file-office, file-pdf, malware-cnc, malware-other, os-windows and server-webapp rule sets to provide coverage for emerging threats from these technologies.
In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, November 26, 2013

Sourcefire VRT Certified Snort Rules Update for 11/26/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 11/26/2013

We welcome the introduction of the newest rule release from the VRT. In this release we introduced 19 new rules and made modifications to 52 additional rules.

There were two changes made to the snort.conf in this release:

The following ports were added to HTTP_PORTS, http_inspect, and Stream5 both:

555
808

The Snort.confs on the example page have been updated:
https://www.snort.org/configurations

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

Avery Tarasov:
28800
28801
28802
28803
28804
28805
28806
28807
28809

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the deleted, exploit-kit, file-flash, file-office and malware-cnc rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Thursday, November 14, 2013

Sourcefire VRT Certified Snort Rules Update for 11/14/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 11/14/2013

We welcome the introduction of the newest rule release from the VRT. In this release we introduced 21 new rules and made modifications to 11 additional rules.

There were two changes made to the snort.conf in this release

The following ports were added to HTTP_PORTS, http_inspect ports, and Stream5's tcp (both) sections:

53331
6173

The Snort.confs on the example page have been updated: https://www.snort.org/configurations

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:
Avery Tarasov:
28404
28405
28406
28540
28541
28542
28543

Thanks to rmkml for his improvement to rule:
28445


In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, exploit-kit, file-office, file-other, malware-backdoor, malware-cnc, malware-tools, pua-adware, pua-toolbars and web-client rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Thursday, October 31, 2013

Sourcefire VRT Certified Snort Rules Update for 10/31/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 10/31/2013

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 27 new rules and made modifications to 7 additional rules.

There were three changes made to the snort.conf in this release:

The following ports were added to HTTP_PORTS, http_inspect ports, and Stream5's tcp (both) sections:

51423
44440
33300
15489

The Snort.confs on the example page have been updated:
https://www.snort.org/configurations

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

Avery Tarasov:
28404
28405
28406


In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, exploit-kit, file-multimedia, file-office, file-pdf, indicator-compromise, malware-cnc, os-mobile and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, October 29, 2013

Sourcefire VRT Certified Snort Rules Update for 10/29/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 10/29/2013

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 63 new rules and made modifications to 78 additional rules.

There was one change made to the snort.conf in this release:

The following port was added to HTTP_PORTS, http_inspect ports, and Stream5's tcp (both) sections:

29991

The Snort.confs on the example page have been updated:
https://www.snort.org/configurations

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

Nick Mavis:
28344


In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, browser-firefox, browser-ie, browser-plugins, exploit-kit, file-flash, file-identify, file-office, file-other, file-pdf, indicator-obfuscation, malware-cnc, malware-other, malware-tools, os-windows and server-other rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, October 22, 2013

Sourcefire VRT Certified Snort Rules Update for 10/22/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 10/22/2013

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 45 new rules and made modifications to 66 additional rules.

There were two changes made to the snort.conf in this release:

The following ports were added to HTTP_PORTS, http_inspect ports, and Stream5's tcp (both) sections:
1533
8082

The Snort.confs on the example page have been updated:
https://www.snort.org/configurations

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

Avery Tarasov:
28255
28285
28293
28294
28295
28296
28297

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the app-detect, blacklist, browser-ie, browser-other, browser-plugins, exploit-kit, file-java, file-multimedia, file-other, file-pdf, indicator-compromise, malware-backdoor, malware-cnc, os-windows, protocol-icmp, protocol-tftp, pua-adware and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Thursday, October 17, 2013

Sourcefire VRT Certified Snort Rules Update for 10/17/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 10/17/2013

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 14 new rules and made modifications to 28 additional rules.

The following ports were added to HTTP_PORTS, http_inspect "ports", and stream5 "both":

3029

The Snort.confs on the example page have been updated:
  https://www.snort.org/configurations

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the app-detect, blacklist, browser-ie, exploit-kit, file-image, file-pdf, malware-cnc and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Monday, October 14, 2013

Sourcefire VRT Certified Snort Rules Update for 10/14/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 10/14/2013

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 1 new rules and made modifications to 8 additional rules.

There were three changes made to the snort.conf in this release:

The following ports were added to HTTP_PORTS, http_inspect "ports", and stream5 "both":

12601
55252
5117

The Snort.confs on the example page have been updated:
https://www.snort.org/configurations

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

James Lay:
28215


In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the browser-ie, browser-plugins and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, September 24, 2013

Sourcefire VRT Certified Snort Rules Update for 09/24/2013, Snort.conf updates

Just released:
Sourcefire VRT Certified Snort Rules Update for 09/24/2013

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 96 new rules and made modifications to 40 additional rules.

There were three changes made to the snort.conf in this release.  The following ports were added to http_inspects "ports" line, stream5's "both" line, and the HTTP_PORTS variable:

8509
7770
1158

The example VRT snort.conf's have been updated at the following address:
https://www.snort.org/configurations

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:
Avery Tarasov:
27965
28004
28012

Yaser Mansour:
28005
28006 (Also special thanks to Avery Tarasov for writing almost the same rule)
28033
28034
28035
28036

James Lay:
28007
28008
28009
28010
28011

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the app-detect, blacklist, browser-ie, deleted, exploit-kit, file-identify, file-office, file-other, indicator-compromise, indicator-obfuscation, indicator-scan, malware-cnc, malware-other, malware-tools and smtp rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Thursday, August 29, 2013

Sourcefire VRT Certified Snort Rules Update for 08/29/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 08/29/2013

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 45 new rules and made modifications to 37 additional rules.

There were changes made to the snort.conf in this release:
The following ports were added to HTTP_PORTS, http_inspect, and stream5 (ports both)
36
818
801
972
4000

The example Snort.conf's have been updated here:
https://www.snort.org/configurations

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

James Lay:
27726
27727
27728

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, browser-ie, browser-plugins, deleted, exploit-kit, file-flash, file-java, file-office, file-pdf, indicator-compromise, indicator-obfuscation, malware-cnc, os-mobile, protocol-dns, pua-adware, server-apache, server-mail, server-other and sql rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Thursday, August 15, 2013

Sourcefire VRT Certified Snort Rules Update for 08/15/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 08/15/2013


We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 19 new rules and made modifications to 31 additional rules.

There were two changes made to the snort.conf in this release:
Ports 1741 and port 8181 were added to the Stream5 "both" configuration line.  The Snort.confs have been updated here: https://www.snort.org/configurations for your use.  Special thanks to "Bram" for pointing this out.

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

Avery Tarasov:
27632
27633

Yaser Mansour
27625
27626
27627
27628
27629
27630
27631

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, file-executable, file-flash, file-image, file-multimedia, file-office, file-other, file-pdf, malware-cnc, os-mobile, server-oracle, server-other and server-webapp rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, June 25, 2013

Sourcefire VRT Certified Snort Rules Update for 06/25/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 06/25/2013


We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 34 new rules and made modifications to 25 additional rules.

There were two changes made to the snort.conf in this release:
Port 3443 was added to HTTP_PORTS, Stream5 both, and http_inspect
Port 50000 was added to HTTP_PORTS, Stream5 both, and http_inspect

The VRT would like to thank the following individuals for their contributions, their rules are included in the Community Ruleset:

Avery Tarasov
26984

Nathan Fowler
26985

I've went ahead and updated our master snort.conf examples from the VRT on the Snort.conf configuration page: https://www.snort.org/configurations

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, browser-ie, browser-other, browser-plugins, deleted, exploit-kit, file-other, malware-cnc, os-mobile, protocol-dns, protocol-ftp, protocol-imap, protocol-tftp and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, June 18, 2013

Sourcefire VRT Certified Snort Rules Update for 06/18/2013, New Categories

Just released:
Sourcefire VRT Certified Snort Rules Update for 06/18/2013

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 28 new rules and made modifications to 48 additional rules.

There were changes made to the snort.conf in this release:

include $RULE_PATH/file-java.rules
include $RULE_PATH/indicator-scan.rules
include $RULE_PATH/os-mobile.rules
include $RULE_PATH/protocol-dns.rules
include $RULE_PATH/protocol-nntp.rules
include $RULE_PATH/protocol-rpc.rules
include $RULE_PATH/protocol-scada.rules
include $RULE_PATH/protocol-snmp.rules
include $RULE_PATH/protocol-telnet.rules
include $RULE_PATH/protocol-tftp.rules
include $RULE_PATH/server-samba.rules


This release introduces new rule categories:

File-Java
Indicator-Scan
Os-Mobile
Protocol-DNS
Protocol-NNTP
Protocol-RPC
Protocol-Scada
Protocol-SNMP
Protocol-Telnet
Protocol-TFTP
Server-Samba


I've went ahead and updated our master snort.conf examples from the VRT on the Snort.conf configuration page: https://www.snort.org/configurations

The VRT would like to thank the following individuals for their contributions:

Avery Tarasov:
26910
26911
26912
26913
26914
26915
26924

Alexandre Menezes:
26916
26917
26918
26919
26920

Paul Bottomley:
26923

Brandon Kendall:
26925


In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, browser-ie, browser-plugins, file-flash, file-java, file-other, file-pdf, indicator-scan, malware-cnc, malware-other, os-mobile, os-windows, protocol-dns, protocol-ftp, protocol-imap, protocol-nntp, protocol-rpc, protocol-scada, protocol-snmp, protocol-telnet, protocol-tftp, server-other, server-samba and sql rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Thursday, June 6, 2013

Sourcefire VRT Certified Snort Rules Update for 06/06/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 06/06/2013


We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 12 new rules and made modifications to 33 additional rules.

There was one change made to the snort.conf in this release.  Port 90 was added to HTTP_PORTS, http_inspect, and stream5.  The Example VRT snort.conf's have been updated: https://www.snort.org/configurations.

The VRT would like to thank the following individuals for their contributions:

Avery Tarasov:
26811
26812

James Lay
26725
26726
26727
26728
26729
26730
26731
26732
26733
26734
26735
26736
26737
26738
26739
26740
26741
26742
26743
26744
26745
26746
26747
26748
26749
26750
26810

Nathan Fowler
26814

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the exploit-kit, file-pdf, malware-cnc and server-iis rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, May 21, 2013

Sourcefire VRT Certified Snort Rules Update for 05/21/2013

Just released:
Sourcefire VRT Certified Snort Rules Update for 05/21/2013

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 57 new rules and made modifications to 68 additional rules.

Port 10000 was added to the snort.conf for http_inspect, stream5, and HTTP_PORTS. The Example VRT snort.conf's have been updated: https://www.snort.org/configurations.

The VRT would like to thank the following individuals for their contributions:

Avery Tarasov
26654
26657
26660
26696
26697

James Lay
26655
26656
26658
26659
26698

Paul Bottomley
26695


In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the blacklist, browser-firefox, browser-ie, browser-plugins, browser-webkit, exploit-kit, file-flash, file-identify, file-image, file-multimedia, file-office, file-pdf, malware-backdoor, malware-cnc, malware-other, os-windows, protocol-ftp, pua-adware and web-client rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!