Wednesday, March 9, 2016

Snort Subscriber Rule Set Update for 03/09/2016

Just released:
Snort Subscriber Rule Set Update for 03/09/2016


We welcome the introduction of the newest rule release from Talos. In this release we introduced 10 new rules and made modifications to 2 additional rules.

There were no changes made to the snort.conf in this release.



Talos's rule release:
Talos has added and modified multiple rules in the browser-other, exploit-kit, malware-cnc, policy-other, protocol-dns, server-mail and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Community Snort Rule Monthly Detection Contest!

Here at Snort, we continue to welcome rule submissions to improve community detection. As a thanks to our community, we like to reward individuals with some cool “Snort swag” items such as our new “Snorty mug”, hoodies, Snort calendar, and other goodies for rule submissions accepted.

For further details, please read on:

Tuesday, March 8, 2016

Snort OpenAppID Detectors have been updated!

An update has been released today for the Snort OpenAppID Detector content.

This release, build 264, includes
  • A total of 2,813 detectors. 
  • It also includes some additional detectors that came in from the open source community. For more details on which contributions were included, we have added them in the AUTHORS file in this package.
Available now for download from our downloads page, we look forward to you downloading and using the new features of 2.9.7.0's and 2.9.8.0's OpenAppID preprocessor and sharing your experiences with the community.


The OpenAppID community has a mailing list specifically dedicated to the exchange and discussion of detector content.  Please visit the mailing lists page to sign up.

Snort++ Build 191 Available Now

Snort++ build 191 is now available on snort.org.  This is the latest monthly update available for download.  You can also get the latest updates from github (snortadmin/snort3) which is updated weekly.

Click below for details:

Snort Subscriber Rule Set Update for 03/08/2016, MSTuesday

Just released:
Snort Subscriber Rule Set Update for 03/08/2016


We welcome the introduction of the newest rule release from Talos. In this release we introduced 69 new rules and made modifications to 8 additional rules.

There were no changes made to the snort.conf in this release.

See below for the details of the release:

Monday, March 7, 2016

Snort 2.9.6.2 is EOL!

Just a notification to remind everyone that Snort 2.9.6.2 is now End of Life (EOL).  In accordance with our EOL policy, and reminders we've posted here on the blog, 2.9.6.2 met it's EOL date today.

We released 2.9.6.2 in July of 2014, and I believe that sets the record for the longest supported version of Snort we've ever had with close to 200 rule releases for this version.

2.9.6.2 lived a good life, but now it's time to upgrade our engines, Snort 2.9.8.0 is the current version of Snort, and we should upgrade immediately.

Thanks for all of your support!

Friday, March 4, 2016

Snort++ Update

Pushed build 190 to github (snortadmin/snort3):
  • fixed console close and remote control disconnect issues
  • added per-thread memcap calculation
  • added statistics counters to host_tracker module
  • new_http_inspect basic URI normalization with configuration options
  • format string cleanup for parser logging
  • fixed conf reload by signal

Thursday, March 3, 2016

Snort Subscriber Rule Set Update for 03/03/2016, Update 2

Just released:
Snort Subscriber Rule Set Update for 03/03/2016


We welcome the introduction of the newest rule release from Talos. In this release we introduced 0 new rules and made modifications to 5 additional rules.

There were no changes made to the snort.conf in this release.



Talos's rule release:
Talos has modified multiple rules in the policy-other rule set to provide coverage for emerging threats from these technologies.


In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Snort Subscriber Rule Set Update for 03/03/2016

Just released:
Snort Subscriber Rule Set Update for 03/03/2016


We welcome the introduction of the newest rule release from Talos. In this release we introduced 186 new rules and made modifications to 821 additional rules.

There were no changes made to the snort.conf in this release.



Talos's rule release:
Talos has added and modified multiple rules in the blacklist, browser-ie, browser-other, browser-plugins, deleted, exploit-kit, file-flash, file-identify, file-image, file-multimedia, file-office, file-other, file-pdf, indicator-compromise, indicator-obfuscation, malware-cnc, netbios, os-windows, policy-other, protocol-pop, protocol-voip, pua-other, server-apache, server-mail, server-oracle, server-other and sql rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Tuesday, March 1, 2016

Snort Subscriber Rule Set Update for 03/01/2016

Just released:
Snort Subscriber Rule Set Update for 03/01/2016


We welcome the introduction of the newest rule release from Talos. In this release we introduced 16 new rules and made modifications to 11 additional rules.

There were no changes made to the snort.conf in this release.



Talos's rule release:
Talos has added and modified multiple rules in the browser-ie, browser-plugins, exploit-kit, file-office, os-windows and server-webapp rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!