Showing posts with label snort. Show all posts
Showing posts with label snort. Show all posts

Tuesday, January 20, 2026

End of Life Announcement for versions of Snort 2 AND Snort 3

Multiple versions of Snort 2 and Snort 3 have reached End of Life and we will no longer publish Snort Talos Rules for these versions as of today.

As of Today we will no longer be supporting the following versions of Snort Talos Rules

Snort 2

2.9.11.1

2.9.13.0

2.9.14.1

2.9.15.1

2.9.16.0

2.9.16.1

2.9.17.0
2.9.19.0

Snort 3

3.0.3.1

3.0.3.4

3.1.0.0

3.1.3.0

3.1.4.0

3.1.5.0

3.1.7.0

3.1.9.0

We encourage All Snort 3 users to use the Talos lightSPD rules package for downloading rules as this singular package contains configurations for every version of Snort 3 and Shared Object rules for all supported versions and architectures, in addition to the latest versions of all rules

Upgrade to the latest version of Snort 3 available here: https://snort.org/downloads 

For more information on the features and advantages of Snort 3 please visit:
https://snort.org/snort3 

For More information on using the Talos lightSPD package please visit:
https://blog.snort.org/2020/12/soft-release-lightspd-new-rules-package.html

For help downloading, installing and configuring Snort 3 please visit:
https://docs.snort.org/rules/

To take advantage of SnortML:
https://blog.snort.org/2024/08/watch-snortml-training-video.html 

To learn more about Snort 3 and Wide String Detection:
https://blog.snort.org/2025/04/in-snort-3.html 

For users who would like to continue to use Snort 2, we encourage you to update to Snort 2.9.20 as soon as possible, which can be found at https://snort.org/downloads . 

Snort 2.9.20 is the version of Snort that we will continue to support for the longest period of time. 

If you have any questions, please feel free to reach out to us at: snort-sub@cisco.com  or join our discord: https://discord.gg/DZpdZDJtSH




Thursday, September 18, 2025

End of Life Announcement for Multiple Versions of Snort 2 and Snort 3

Multiple versions of Snort 2 and Snort 3 will be reaching End of Life this year.

As of 12/18/2025 the following versions of Snort 2 will have reached end of life and we will no longer publish Snort Talos Rules for these versions as a result, the following versions of Snort 2 will no longer be supported: 

2.9.11.1
2.9.13.0
2.9.14.1
2.9.15.1
2.9.16.0
2.9.16.1
2.9.17.0
2.9.18.1
2.9.19.0 

As of 12/18/2025, all versions of Snort 3 prior to and including Snort 3.1.9.0 will reach end of life and will no longer be supported.  

We encourage All Snort 3 users to use the Talos lightSPD rules package for downloading rules as this singular package contains configurations for every version of Snort 3 and Shared Object rules for all supported versions and architectures, in addition to the latest versions of all rules

Upgrade to the latest version of Snort 3 available here: https://snort.org/downloads 

For more information on the features and advantages of Snort 3 please visit:
https://snort.org/snort3 

For More information on using the Talos lightSPD package please visit:
https://blog.snort.org/2020/12/soft-release-lightspd-new-rules-package.html

For help downloading, installing and configuring Snort 3 please visit:
https://docs.snort.org/rules/

To take advantage of SnortML:
https://blog.snort.org/2024/08/watch-snortml-training-video.html 

To learn more about Snort 3 and Wide String Detection:
https://blog.snort.org/2025/04/in-snort-3.html 

For users who would like to continue to use Snort 2, we encourage you to update to Snort 2.9.20 as soon as possible, which can be found at https://snort.org/downloads . 

Snort 2.9.20 is the version of Snort that we will continue to support for the longest period of time. 

If you have any questions, please feel free to reach out to us at: snort-sub@cisco.com  or join our discord: https://discord.gg/DZpdZDJtSH


Friday, April 4, 2025

Adding Improved Wide String Detection to Snort 3

By Chris Morrison

In Snort 3.6.2.0, the team has added new modifiers for the "content” option to simplify detection against multi-byte character strings.

For content matches, “width” and “endian” options allow users to modify the content to match against simple wide character strings without manually adding null bytes into the patterns. This makes rule writing easier and more maintainable against targets that use multi-byte character strings, as is common in file metadata or modern string encodings.


Width allows a simple expansion of the content from 8-bit character width to a specified width of 8, 16, or 32 bits. Note that 8 bits is the default behavior and does not impact detected content. 

 

# Match "hello" encoded with 32 bits per character in big endian  

content:"|000000|h|000000|e|000000|l|000000|l|000000|o";  

content:"hello", width 32; 

 

Endian further modifies the width option’s expansion to control the endianness of the expanded character with “big” (as the default) and “little” options. Combining these two options, we can easily flex our detection patterns to match on a variety of string encodings. For example, content: “Talos”, width 32, endian little; would detect on “Talos” encoded as a UTF-32-LE string. 

 

# Match "Talos" encoded with 32 bits per character in little endian content:"T|000000|a|000000|l|000000|o|000000|s|000000|"; 

content:"Talos",width 32,endian little; 

 

To showcase how the width and endian modifiers can make rules more maintainable, consider the existing malware detection in Snort SID 55927. This rule detects several highly suspect strings within a target binary; however, these strings are UTF-16-LE encoded. Here is the simplified rule in old content syntax with null bytes manually added: 

 

alert file ( 

msg:"MALWARE-CNC Win.Dropper.LemonDuck variant script download attempt"; 

file_data; 

content:"|00|%|00|u|00|s|00|e|00|r|00|n|00|a|00|m|00|e|00|%|00||00|%|00|c|00|o|00|m|00|p|00|u|00|t|00|e|00|r|00|n|00|a|00|m|00|e|00|%|00|*|00|",fast_pattern,nocase; 

content:"W|00|S|00|c|00|r|00|i|00|p|00|t|00|.|00|S|00|h|00|e|00|l|00|l|00|",nocase; 

content:"D|00|o|00|w|00|n|00|L|00|o|00|a|00|d|00|S|00|t|00|r|00|i|00|n|00|g|00|",nocase; 

) 

 

 

Here is an example of the new syntax, which makes the rule much easier to follow: 

 

alert file ( 

msg:"MALWARE-CNC Win.Dropper.LemonDuck variant script download attempt"; 

file_data; 

content:"%username%%computername%*", fast_pattern, nocase, width 16, endian little; 

content:"WScript.Shell", nocase, width 16, endian little; 

content:"DownLoadString", nocase, width 16, endian little; 

) 

 

As we can see, if the new rule were to have hits in our environment, we would be able to understand what the rule is alerting to much faster than the original syntax. ClamAV and Yara users will likely be familiar with this usage because the combination of “endian little” and “width 16” is functionally identical to the languages’ wide modifiers. 


These new features are available in Snort 3.6.2.0 and later. More documentation on these options is available in the Snort 3 Rule Writing Guide. 


If you have any questions, feel free to reach out to us via: snort-users@lists.snort.org or join our Snort Discord.


Thursday, September 26, 2024

Changes to the Snort Sample IP Block List

Effective today, we have made some changes to the Snort Sample IP Block List available on Snort.org

The Snort Sample IP Blocklist has been a steady component of our open-source Snort community since its launch. It was originally provided so the community could test the functionality of their Snort installation, and it was never intended to be users’ sole source of IP blocking.

Traditionally, this is list of suggested IPs to block based on other open-source IP block lists. But over the past several years, we have seen an increasing number of users relying on the Snort Sample IP Blocklist as their primary source of IP Blocking, which may lead to a false sense of protection from threats.   

To ensure the intention and legal usage of this blocklist is clear to all our users, we will be enabling a “click-to-accept” terms and conditions box for users to access the Snort Sample IP Blocklist hosted on Snort.org. This change will outline the legal terms and conditions for use of the blocklist, which clearly documents the intended use of the data.  

We will continuously update the Snort Sample IP Blocklist on Snort.org regularly and provide it free to all users to ensure that Snort is functioning as intended. 

You can download the Snort Sample IP Block List here.

Thanks,

The Snort Team


Monday, August 26, 2024

Upcoming changes to the Snort.org Sample IP Blocklist

We will be making some changes to the Snort Sample IP Block List on Sept. 26, 2024. 

The Snort Sample IP Blocklist has been a steady component of our open-source Snort community since its launch. It was originally provided so the community could test the functionality of their Snort installation, and it was never intended to be users’ sole source of IP blocking. 

The Snort Sample IP Block List is a list of suggested IPs to block based on other open-source IP block lists. Over the last several years, we have seen an increasing number of users relying on the Snort Sample IP Blocklist as their primary source of IP Blocking, which may be leading to a false sense of protection from threats.    

To ensure the intention and legal usage of this blocklist is clear to all our users, we will be enabling a “click-to-accept” terms and conditions box for users to access the Snort Sample IP Blocklist hosted on Snort.org.   

This change will outline the legal terms and conditions for use of the blocklist, which clearly documents the intended use of the data.  

We will continue to update the Snort Sample IP Blocklist on Snort.org regularly and provide it free to all users, to ensure that Snort is functioning as intended.  After Sept. 26, 2024, access to the list will require users to click to accept the terms and conditions. 

 
If you have any questions, feel free to reach out to us via:snort-users@lists.snort.org 
 
Or join our Discord https://discord.gg/Pj3usE9CZ7

Tuesday, January 25, 2022

Snort rule update for Jan. 25, 2022 — And an update to our supported operating systems

The newest SNORTⓇ rule update from Cisco Talos is now available.

This release includes several rules to protect against malicious PHP command shells in Ajax that are sometimes used in cyber attacks. 

Here's a full breakdown of the rest of Tuesday's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
3 0140

Tuesday, December 14, 2021

Snort rule update for Dec. 14, 2021 — Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for many of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this month, view all of them on Microsoft's security update page. Since our researchers are heads-down working on the Log4j vulnerability, we were not able to release a full Patch Tuesday blog post this month on the Talos site.

Here's a breakdown of this afternoon's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
00397

Monday, December 6, 2021

Open-source version of Snort 2.9.19.0 available now

 SNORTⓇ released its newest open-source version, 2.9.19.0, this morning.

You can download this version on Snort.org. As you may remember, version 2.9.18.0 reached its end-of-life last week, so anyone using that version should update immediately. 

Tuesday, November 30, 2021

Snort rule update for Nov. 30, 2021

The newest SNORTⓇ rule update from Cisco Talos is now available.

Tuesday morning's release includes a new rule to protect against the high-profile DarkSide ransomware. The group, also known as DarkMatter, targeted several high-profile companies across the globe this year, including two companies in the U.S. food and agriculture sector. 

This new rule detects when the ransomware attempts to make an outbound connection.

Here's a full breakdown of the rest of today's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
10 0195

Wednesday, November 3, 2021

Snort 3.1.16.0 has been released!

   

The SNORTⓇ team recently released a new version of Snort 3 on Snort.org and the Snort 3 GitHub.

 
Snort 3.1.16.0 contains several new features and bug fixes. Here's a complete rundown of what's new in this version. Users are encouraged to update as soon as possible and to upgrade to Snort 3 if they have not already done so.

Changes in this release (since 3.1.15.0):

  • appid: during initialization, skip loading of Lua detectors that don't have validate function
  • appid: in packet threads, skip loading of detectors that don't have validate function on reload
  • appid: provide API to give client_app_detection_type
  • codec: geneve - ensure injected packets have geneve port in outer udp header
  • detection: refactor mpse serialization
  • detection: rename PortGroup to the more apt RuleGroup (and related)
  • detection: replace PortGroup::alloc/free with ctor/dtor
  • doc: add SIP built-in rule documentation
  • doc: update built-in rule doc for SMTP, IMAP and POP inspectors
  • doc: update built-in rules documentation for dns module
  • doc: update built-in rules documentation for ftp-telnet
  • doc: updated builtin rules documentation for gtp module
  • flow: fix warning in flow_cache.cc
  • flow: use the same pkt_type to link and unlink unidirectional flows
  • http2_inspect: refactor decoded_headers_buffer for hpack decoding
  • http_inspect: eliminate cumulative js data processing
  • http_inspect: handle unordered PDUs for inline/external JavaScript normalization
  • http_inspect: improve file decompression
  • hyperscan: sort patterns for dump / load stability
  • ips: correct fast pattern port group counts
  • mpse: add md5 check to deserialization
  • reload: add logs to track reload process
  • reload: move out reload progress flag to reload tracker
  • search_engine: support hyperscan serialization
  • search_engine: support port group serialization
  • sip: track memory for sip sessions
  • ssl: disable inspection on alert only at fatal level
  • stream_tcp: fix init_wscale() to take into account the DECODE_TCP_WS flag
  • tcp: remove the obsolete GNUC block from TcpOption::next()
  • tcp: stop on the EOL option in TcpOptIteratorIter::operator++()
  • utils: add get methods to peek in internal buffer
  • utils: correct Normalizer's output upon the next scan
  • wizard: update globbing and max_pattern

Snort 3 is the next generation of the Snort Intrusion Prevention System. The GitHub page will walk users through what Snort 3 has to offer and guide users through the steps of getting set up — from download to demo. Users unfamiliar with Snort should start with the Snort Resources page and the Snort 101 video series. 

You can subscribe to Talos' newest rule detection functionality for as low as $29 a year with a personal account. Be sure and see our business pricing as well here. Make sure and stay up to date to catch the most emerging threats.

Friday, October 29, 2021

Snort 3.1.15.0 has been released -- Check out this new version!

   

The SNORTⓇ team recently released a new version of Snort 3 on Snort.org and the Snort 3 GitHub.

 

Snort 3.1.15.0 contains several new features and bug fixes. Here's a complete rundown of what's new in this version. Users are encouraged to update as soon as possible and to upgrade to Snort 3 if they have not already done so.

Since the API inside of Snort3 has changed with this version, if you are using the LightSPD package, you will need to use the latest release (posted yesterday, October 28, 2021).

Tuesday, October 12, 2021

Snort rule update for Oct. 12, 2021 — Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for many of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this month, head to the Talos blog.

Here's a breakdown of this afternoon's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
10378

Tuesday, September 14, 2021

Snort rule update for Sept. 14, 2021 — Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for many of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this month, head to the Talos blog.

Here's a breakdown of this afternoon's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
20174

Wednesday, September 1, 2021

Snort version 2.9.18.1 has been released

We released the latest version of Snort 2.9, SNORTⓇ version 2.9.18.1, this afternoon. 

This version is a very small update that fixes a possible memory corruption issue in the SMB preprocessor. If you haven't already, we also encourage users to upgrade to Snort 3, which includes a new rule parser and rule syntax, support for multiple packet-processing threads, and much more.

Here's a rundown of what's new in 2.9.18.1:

Snort OpenAppID Detectors have been updated

SNORTⓇ released a new update today for its OpenAppID Detector content.

This release — build 346 — includes:
  • 3,066 detectors. 
  • Additional detectors from the open-source community. For more details on which contributions were included, we have added them to the "Authors" file in this package.
The release is available now on our Downloads page. We look forward to users downloading and using the new features. If you have any feedback,  please share it with the OpenAppID mailing list.

The OpenAppID package is also compatible with our most recent Snort 3 releases.

Tuesday, July 27, 2021

Snort rule update for July 27, 2021

Cisco Talos released the newest SNORTⓇ ruleset this morning.

We released the rule update overnight, featuring new protections against several malware families. Among the coverage are a few rules to detect a new Trickbot module that spies on users by creating an attacker-controlled virtual machine.

There are also new protections against the SeriousSAM vulnerability recently discovered in Windows 10 and 11. The vulnerability could allow an attacker to install programs, edit data or create new accounts with full user rights.

Here's a full breakdown of Monday night's release:

Shared object rulesModified shared object rulesNew rulesModified rules
3 0242

Thursday, July 8, 2021

Snort rule update for July 8, 2021

The newest Cisco Talos rule release for SNORTⓇ is here.

Thursday's ruleset includes new protections against two recently disclosed vulnerabilities in Cisco Business Process Automation. An attacker could exploit these vulnerabilities to elevate their privileges to the level of Administrator on the targeted machine.

We also want to remind everyone that Snort version 2.9.15.0 has officially reached its end of life. Any users on that version need to update as soon as possible.

Here's a full breakdown of today's release:

Shared object rulesModified shared object rulesNew rulesModified rules
8 002

Tuesday, June 29, 2021

Snort rule update for June 29, 2021

Cisco Talos released the newest SNORTⓇ ruleset this morning.

Tuesday's rule update includes new rules to protect against the "Victory" backdoor recently being used by a state-sponsored APT as part of a surveillance operation. There are also new rules associated with the same attack that block an RTF file the attackers use with the RoyalRoad weaponizer.

Talos also released coverage for a recently disclosed vulnerability in Cisco's Adaptive Security Appliance that is being exploited in the wild.

Here's a full breakdown of today's release:

Shared object rulesModified shared object rulesNew rulesModified rules
0 2371

Tuesday, June 15, 2021

Snort rule update for June 15, 2021

Cisco Talos released the newest rule set for SNORTⓇ this morning.

Tuesday's rule release provides new protections against the IPsec Helper backdoor. The group behind the backdoor, known as Agrius, recently deployed a similar backdoor as part of a wiper malware campaign. 

Here's a full breakdown of this release:

Shared object rulesModified shared object rulesNew rulesModified rules
14 01111

Wednesday, May 12, 2021

Snort OpenAppID Detectors have been updated

SNORTⓇ released a new update today for its Snort OpenAppID Detector content.

This release — build 342 — includes:
  • 2,971 detectors. 
  • Additional detectors from the open-source community. For more details on which contributions were included, we have added them to the "Authors" file in this package.
The release is available now on our Downloads page. We look forward to users downloading and using the new features. If you have any feedback,  please share with the OpenAppID mailing list.

The OpenAppID package is also compatible with our Snort 3.x release.