# Feedback & Support

**URL:** https://community.emergingthreats.net/c/feedback-support/8.md

[Latest](https://community.emergingthreats.net/latest.md) · [Categories](https://community.emergingthreats.net/categories.md) · [Tags](https://community.emergingthreats.net/tags.md)

---

## [About the Feedback & Support category](https://community.emergingthreats.net/t/about-the-feedback-support-category/24)

<div class="topic-metadata">

**Author:** [@dkaczmark](https://community.emergingthreats.net/u/dkaczmark)\
**Replies:** 0

</div>

Unofficial Support and Feedback for ET products.

---

## [False Positive Report - SID 2049637 (Bitbucket CVE-2022-1471 Vulnerable Server Detected 7.17.x–7.21.15) matches ALL 7.21.x including patched versions](https://community.emergingthreats.net/t/false-positive-report-sid-2049637-bitbucket-cve-2022-1471-vulnerable-server-detected-7-17-x-7-21-15-matches-all-7-21-x-including-patched-versions/3388)

<div class="topic-metadata">

**Author:** [@sonzu](https://community.emergingthreats.net/u/sonzu)\
**Replies:** 1\
**Last updated:** [July 23, 2026, 4:33pm UTC](https://community.emergingthreats.net/t/false-positive-report-sid-2049637-bitbucket-cve-2022-1471-vulnerable-server-detected-7-17-x-7-21-15-matches-all-7-21-x-including-patched-versions/3388 "2026-07-23T16:33:31Z")

</div>

Rule (rev 1, 2023-12-12) : drop http \[$HOME\_NET,$HTTP\_SERVERS\] any → any any (msg:“ET WEB\_SPECIFIC\_APPS Atlassian Bitbucket CVE-2022-1471 Vulnerable Server Detected Version 7.17.x - 7.21.15”; flow:established,to\_client;…

---

## [Top most triggered signatures?](https://community.emergingthreats.net/t/top-most-triggered-signatures/3366)

<div class="topic-metadata">

**Author:** [@fawlatedow](https://community.emergingthreats.net/u/fawlatedow)\
**Replies:** 0\
**Last updated:** [June 27, 2026, 8:00pm UTC](https://community.emergingthreats.net/t/top-most-triggered-signatures/3366 "2026-06-27T20:00:30Z")

</div>

hey all! Was wondering if there is some sort of a public “these are the ETOPEN signatures we see trigger most often” list somewhere? Thanks!

---

## [False positive in SID 2067295 (CVE-2025-58180 OctoPrint upload) - pcre matches multipart line terminator](https://community.emergingthreats.net/t/false-positive-in-sid-2067295-cve-2025-58180-octoprint-upload-pcre-matches-multipart-line-terminator/3356)

<div class="topic-metadata">

**Author:** [@pedrolamas](https://community.emergingthreats.net/u/pedrolamas)\
**Replies:** 2\
**Last updated:** [June 15, 2026, 3:15pm UTC](https://community.emergingthreats.net/t/false-positive-in-sid-2067295-cve-2025-58180-octoprint-upload-pcre-matches-multipart-line-terminator/3356 "2026-06-15T15:15:57Z")

</div>

This rule fires on any legitimate multipart file upload to /api/files/local, not just command-injection attempts. Root cause In the pcre, the skip class \[^\\x26\]\*? only stops at &, so it walks past the closing " of the f…

---

## [Access to ET PRO Rules](https://community.emergingthreats.net/t/access-to-et-pro-rules/3318)

<div class="topic-metadata">

**Author:** [@jannitand](https://community.emergingthreats.net/u/jannitand)\
**Replies:** 2\
**Last updated:** [May 13, 2026, 3:24pm UTC](https://community.emergingthreats.net/t/access-to-et-pro-rules/3318 "2026-05-13T15:24:30Z")

</div>

Hello, Where can I find information about how to subscribe to ET PRO rule updates as well as price information? Thank you!

---

## [False positive for 2067921 ET MALWARE PureLogs Stealer CnC ping Request](https://community.emergingthreats.net/t/false-positive-for-2067921-et-malware-purelogs-stealer-cnc-ping-request/3215)

<div class="topic-metadata">

**Author:** [@grodriguez](https://community.emergingthreats.net/u/grodriguez)\
**Replies:** 2\
**Last updated:** [February 27, 2026, 5:41pm UTC](https://community.emergingthreats.net/t/false-positive-for-2067921-et-malware-purelogs-stealer-cnc-ping-request/3215 "2026-02-27T17:41:20Z")

</div>

Hi everyone, We are observing consistent false positives triggered by SID 2067921 (“ET MALWARE PureLogs Stealer CnC ping Request”). The rule is rev 1 and was created yesterday (2026\_02\_25) yet we have already received a…

---

## [Potential False Positive for 2009099 being triggered by Aurora iOS app to AWS IP Addresses](https://community.emergingthreats.net/t/potential-false-positive-for-2009099-being-triggered-by-aurora-ios-app-to-aws-ip-addresses/3209)

<div class="topic-metadata">

**Author:** [@keysox](https://community.emergingthreats.net/u/keysox)\
**Replies:** 1\
**Last updated:** [February 23, 2026, 7:27pm UTC](https://community.emergingthreats.net/t/potential-false-positive-for-2009099-being-triggered-by-aurora-ios-app-to-aws-ip-addresses/3209 "2026-02-23T19:27:55Z")

</div>

I am reporting a potential False Positive for SID: 2009099 (ET P2P ThunderNetwork UDP Traffic). This rule is triggering from the My Aurora Forecast & Alerts iOS app. The traffic is directed to qt-houston.bronze.systems (…

---

## [Bug: SID 2064326 has severity:1 but is labeled "ET INFO"](https://community.emergingthreats.net/t/bug-sid-2064326-has-severity-1-but-is-labeled-et-info/3171)

<div class="topic-metadata">

**Author:** [@Hans2026](https://community.emergingthreats.net/u/Hans2026)\
**Replies:** 4\
**Last updated:** [January 21, 2026, 3:33pm UTC](https://community.emergingthreats.net/t/bug-sid-2064326-has-severity-1-but-is-labeled-et-info/3171 "2026-01-21T15:33:05Z")

</div>

Rule SID 2064326 “ET INFO Python aiohttp User-Agent Observed Inbound” has conflicting severity indicators, causing false positives in downstream security tools. This rule has: severity: 1 in Suricata alert output (cri…

---

## [Rule categories in emerging-all.rules & etpro-all.rules](https://community.emergingthreats.net/t/rule-categories-in-emerging-all-rules-etpro-all-rules/3159)

<div class="topic-metadata">

**Author:** [@tgreen](https://community.emergingthreats.net/u/tgreen)\
**Replies:** 1\
**Last updated:** [January 12, 2026, 5:26pm UTC](https://community.emergingthreats.net/t/rule-categories-in-emerging-all-rules-etpro-all-rules/3159 "2026-01-12T17:26:25Z")

</div>

Hey ET folks, can you confirm that etpro-all.rules and emerging-all.rules contain all categories except blockrules?

---

## [False Positive Report for ET JA3 Rule 2028802 (Possible Adware blocking TV streaming)](https://community.emergingthreats.net/t/false-positive-report-for-et-ja3-rule-2028802-possible-adware-blocking-tv-streaming/3135)

<div class="topic-metadata">

**Author:** [@Armani](https://community.emergingthreats.net/u/Armani)\
**Replies:** 1\
**Last updated:** [December 15, 2025, 8:03pm UTC](https://community.emergingthreats.net/t/false-positive-report-for-et-ja3-rule-2028802-possible-adware-blocking-tv-streaming/3135 "2025-12-15T20:03:41Z")

</div>

Hello Proofpoint Emerging Threats Team, I am reporting a false positive alert generated by the Suricata rule with SID 2028802, which is incorrectly flagging legitimate traffic from a smart TV streaming service as adware…

---

## [Bug in emerging-ciarmy.rules?](https://community.emergingthreats.net/t/bug-in-emerging-ciarmy-rules/3124)

<div class="topic-metadata">

**Author:** [@mgjk](https://community.emergingthreats.net/u/mgjk)\
**Replies:** 4\
**Last updated:** [December 4, 2025, 9:37pm UTC](https://community.emergingthreats.net/t/bug-in-emerging-ciarmy-rules/3124 "2025-12-04T21:37:50Z")

</div>

I downloaded the latest ruleset and I’m comparing it with the master list https://cinsscore.com/list/ci-badguys.txt. The master list contains 15,000 addresses (they say they capped the list to 15,000), But what’s weird…

---

## [False positive on google.com.onion AP check](https://community.emergingthreats.net/t/false-positive-on-google-com-onion-ap-check/3120)

<div class="topic-metadata">

**Author:** [@lukashino](https://community.emergingthreats.net/u/lukashino)\
**Replies:** 2\
**Last updated:** [December 2, 2025, 3:42pm UTC](https://community.emergingthreats.net/t/false-positive-on-google-com-onion-ap-check/3120 "2025-12-02T15:42:47Z")

</div>

Hey, I’d like to reach out to consult (a quite likely possible) FP of a SID EveBox Rules This SID fires every time phones connect to the network - apparently, due to Samsung’s “Detect suspicious networks” feature, whic…

---

## [Mislabelled CVE in Emerging Threats Rule sid:2029154, 2029155](https://community.emergingthreats.net/t/mislabelled-cve-in-emerging-threats-rule-sid-2029154-2029155/3053)

<div class="topic-metadata">

**Author:** [@paolo.ahn](https://community.emergingthreats.net/u/paolo.ahn)\
**Replies:** 1\
**Last updated:** [September 29, 2025, 9:54pm UTC](https://community.emergingthreats.net/t/mislabelled-cve-in-emerging-threats-rule-sid-2029154-2029155/3053 "2025-09-29T21:54:53Z")

</div>

Msg fields for SIDs 2029154 and 2029155 contain a typo CVE-2019-118396 → please change to CVE-2019-18396 to match NVD/Unit42 references. ※NVD - CVE-2019-18396

---

## [Opnsense suricata rule update for ET Telemetry](https://community.emergingthreats.net/t/opnsense-suricata-rule-update-for-et-telemetry/1952)

<div class="topic-metadata">

**Author:** [@planetf1](https://community.emergingthreats.net/u/planetf1)\
**Replies:** 25\
**Last updated:** [September 24, 2025, 3:21pm UTC](https://community.emergingthreats.net/t/opnsense-suricata-rule-update-for-et-telemetry/1952 "2025-09-24T15:21:58Z")

</div>

I’m running opnsense 24.7.3 & have been using ET Telemetry Pro for about 4 months. I’m seeing various errors like 2024-09-09T06:00:02 Error send\_heartbeat.py unexpected result from https://opnsense.emergingthreat…

---

## [Incorrect CVE References in Jenkins Exploit Signatures](https://community.emergingthreats.net/t/incorrect-cve-references-in-jenkins-exploit-signatures/3000)

<div class="topic-metadata">

**Author:** [@paolo.ahn](https://community.emergingthreats.net/u/paolo.ahn)\
**Replies:** 0\
**Last updated:** [August 28, 2025, 1:29am UTC](https://community.emergingthreats.net/t/incorrect-cve-references-in-jenkins-exploit-signatures/3000 "2025-08-28T01:29:05Z")

</div>

I found incorrect CVE references in the Jenkins exploit rules of emerging-all.rules SID 2060509: References should be CVE-2018-1000861 and CVE-2019-1003000, not 2018-100086 / 2019-100300. SID 2027350 / 2027349: Metada…

---

## [Mislabelled CVE in Emerging Threats Rule sid:2063646](https://community.emergingthreats.net/t/mislabelled-cve-in-emerging-threats-rule-sid-2063646/2921)

<div class="topic-metadata">

**Author:** [@paolo.ahn](https://community.emergingthreats.net/u/paolo.ahn)\
**Replies:** 1\
**Last updated:** [July 24, 2025, 2:42pm UTC](https://community.emergingthreats.net/t/mislabelled-cve-in-emerging-threats-rule-sid-2063646/2921 "2025-07-24T14:42:32Z")

</div>

In rule sid:2063646, the CVE ID “CVE-2025-222066” mentioned in the msg field appears to be incorrect and should be “CVE-2025-22206” instead.

---

## [Commented Out Rules](https://community.emergingthreats.net/t/commented-out-rules/2711)

<div class="topic-metadata">

**Author:** [@BOBIBOO](https://community.emergingthreats.net/u/BOBIBOO)\
**Replies:** 2\
**Last updated:** [May 7, 2025, 8:00pm UTC](https://community.emergingthreats.net/t/commented-out-rules/2711 "2025-05-07T20:00:59Z")

</div>

Hello, I’m an undergraduate student in South Korea currently working on a malware detection system using Suricata. While reviewing the ET Open Ruleset, I noticed that some rules are commented out (i.e., disabled with #)…

---

## [Empty rules with ET Pro Telemetry Opnsense](https://community.emergingthreats.net/t/empty-rules-with-et-pro-telemetry-opnsense/2490)

<div class="topic-metadata">

**Author:** [@Freewheelin](https://community.emergingthreats.net/u/Freewheelin)\
**Replies:** 21\
**Last updated:** [March 27, 2025, 1:32pm UTC](https://community.emergingthreats.net/t/empty-rules-with-et-pro-telemetry-opnsense/2490 "2025-03-27T13:32:44Z")

</div>

Hello: I am running OPNsense 25.1.2 with suricata 7.0.8\_2. I installed the ET Pro Telemetry plugin and input my token. When I selected and downloaded the rules I found that some of the rulesets were empty ( Et/compromise…

---

## [Suricata/ET Pro picked this up, help diagnosing please](https://community.emergingthreats.net/t/suricata-et-pro-picked-this-up-help-diagnosing-please/2557)

<div class="topic-metadata">

**Author:** [@jacgfxgeek](https://community.emergingthreats.net/u/jacgfxgeek)\
**Replies:** 2\
**Last updated:** [March 25, 2025, 12:18am UTC](https://community.emergingthreats.net/t/suricata-et-pro-picked-this-up-help-diagnosing-please/2557 "2025-03-25T00:18:28Z")

</div>

Hi I am a new subscriber to ET Pro Telemetry, and a new Opnsense user, so please feel free to enlighten me. Yesterday I installed ET Pro and today I got the following alert. I have searched online, but results are slim…

---

## [Rule failed error](https://community.emergingthreats.net/t/rule-failed-error/2471)

<div class="topic-metadata">

**Author:** [@EMTUser](https://community.emergingthreats.net/u/EMTUser)\
**Replies:** 1\
**Last updated:** [February 24, 2025, 6:58pm UTC](https://community.emergingthreats.net/t/rule-failed-error/2471 "2025-02-24T18:58:29Z")

</div>

Hi, Downloaded emerging rules from Proofpoint Emerging Threats Rules The following rule is found in http://rules.emergingthreats.net/open/snort-2.9.0/rules/emerging-trojan.rules updated on 2025\_02\_22 . alert tcp $EXTE…

---

## [Keep getting spammed with ET SHELLCODE Common 0a0a0a0a Heap Spray String from an address. Is this anything serious?](https://community.emergingthreats.net/t/keep-getting-spammed-with-et-shellcode-common-0a0a0a0a-heap-spray-string-from-an-address-is-this-anything-serious/2416)

<div class="topic-metadata">

**Author:** [@zara](https://community.emergingthreats.net/u/zara)\
**Replies:** 4\
**Last updated:** [February 8, 2025, 7:19am UTC](https://community.emergingthreats.net/t/keep-getting-spammed-with-et-shellcode-common-0a0a0a0a-heap-spray-string-from-an-address-is-this-anything-serious/2416 "2025-02-08T07:19:16Z")

</div>

I’ve heard this code detects false positives all the time. Could this be a ddos attempt? I’ve detected some degraded network performance since this began. However, my modem is dying. I keep getting spammed by this IP: 65…

---

## [ET Prrofpoint flowbit issues (opnsense)](https://community.emergingthreats.net/t/et-prrofpoint-flowbit-issues-opnsense/2245)

<div class="topic-metadata">

**Author:** [@Cjack](https://community.emergingthreats.net/u/Cjack)\
**Replies:** 4\
**Last updated:** [December 10, 2024, 8:07pm UTC](https://community.emergingthreats.net/t/et-prrofpoint-flowbit-issues-opnsense/2245 "2024-12-10T20:07:05Z")

</div>

How do I resolve these issues? The started appearing several weeks ago. The issue related to the OneLouderHeader flowbit issue started occurring within the past 2 weeks. 00|Warning|suricata|\[101447\] – flowbit ‘ET.OneLou…

---

## [Snort3 rules failed](https://community.emergingthreats.net/t/snort3-rules-failed/2131)

<div class="topic-metadata">

**Author:** [@EMTUser](https://community.emergingthreats.net/u/EMTUser)\
**Replies:** 1\
**Last updated:** [November 19, 2024, 6:08pm UTC](https://community.emergingthreats.net/t/snort3-rules-failed/2131 "2024-11-19T18:08:14Z")

</div>

Hi, Loading my\_dns.rules: ERROR: my\_dns.rules:70 !any is not allowed: !\[$SMTP\_SERVERS,$DNS\_SERVERS\]. Finished my\_dns.rules: Loading rule args: Loading my\_policy.rules: ERROR: my\_policy.rules:146 !any is not allowed…

---

## [Emerging Threats Supported](https://community.emergingthreats.net/t/emerging-threats-supported/2022)

<div class="topic-metadata">

**Author:** [@Ronlad](https://community.emergingthreats.net/u/Ronlad)\
**Replies:** 0\
**Last updated:** [October 2, 2024, 9:11am UTC](https://community.emergingthreats.net/t/emerging-threats-supported/2022 "2024-10-02T09:11:05Z")

</div>

Hi, good day! I was wondering if Emerging Threats supports CSV format or adheres to STIX/TAXII standards 1.0, 1.1, and 2.0, as we are planning to integrate this into FortiSIEM threat intelligence. However, we can’t find…

---

## [PigButcher Credential Phish Landing Page Rules Error on Suricata 7](https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939)

<div class="topic-metadata">

**Author:** [@ar3s](https://community.emergingthreats.net/u/ar3s)\
**Replies:** 6\
**Last updated:** [September 9, 2024, 5:33pm UTC](https://community.emergingthreats.net/t/pigbutcher-credential-phish-landing-page-rules-error-on-suricata-7/1939 "2024-09-09T17:33:46Z")

</div>

Hi All, 3 Rules from \[Ruleset Update Summary - 2024/08/28 - v10676\] are causing errors on suricata version 7 due to http\_content\_type misplacement. sid:2055541 sid:2055542 sid:2055543 Current rule: alert http $EXTE…

---

## [7.0.3 Changelogs](https://community.emergingthreats.net/t/7-0-3-changelogs/1901)

<div class="topic-metadata">

**Author:** [@paccy](https://community.emergingthreats.net/u/paccy)\
**Replies:** 2\
**Last updated:** [August 26, 2024, 4:44pm UTC](https://community.emergingthreats.net/t/7-0-3-changelogs/1901 "2024-08-26T16:44:53Z")

</div>

Hi guys, In case you don’t know all the suricata 7.0.3 changelog links found here Proofpoint Emerging Threats Rules give a 404 error.

---

## [Rule failed](https://community.emergingthreats.net/t/rule-failed/1830)

<div class="topic-metadata">

**Author:** [@EMTUser](https://community.emergingthreats.net/u/EMTUser)\
**Replies:** 3\
**Last updated:** [July 25, 2024, 5:39am UTC](https://community.emergingthreats.net/t/rule-failed/1830 "2024-07-25T05:39:45Z")

</div>

Hi, Downloaded emerging rules from Proofpoint Emerging Threats Rules The following rule is found in http://rules.emergingthreats.net/open/snort-2.9.0/rules/emerging-trojan.rules updated on 2024\_06\_21 . alert tcp $HOME…

---

## [MITRE ATT&CK Additions/Modifications - A Community Discussion](https://community.emergingthreats.net/t/mitre-att-ck-additions-modifications-a-community-discussion/1753)

<div class="topic-metadata">

**Author:** [@James](https://community.emergingthreats.net/u/James)\
**Replies:** 0\
**Last updated:** [June 23, 2024, 10:33am UTC](https://community.emergingthreats.net/t/mitre-att-ck-additions-modifications-a-community-discussion/1753 "2024-06-23T10:33:16Z")

</div>

Hey folks, I am in the process of populating our internal tooling with as much relevant MITRE ATT&CK (enterprise-attack for now) metadata as possible so that we can flesh out existing rules as well as our new rules with…

---

## [Doc.emergingthreats.net, Reference information](https://community.emergingthreats.net/t/doc-emergingthreats-net-reference-information/1191)

<div class="topic-metadata">

**Author:** [@Oppressed1192](https://community.emergingthreats.net/u/Oppressed1192)\
**Replies:** 5\
**Last updated:** [March 18, 2024, 9:25pm UTC](https://community.emergingthreats.net/t/doc-emergingthreats-net-reference-information/1191 "2024-03-18T21:25:55Z")

</div>

Hello, I’m new to the Suricata world, and I keep seeing ET rules with references to the subdomain doc, however, this subdomain doesn’t resolve. Where can I find more information on specific SIDs that are in the Emerging …

---

## [ETPro Feedback](https://community.emergingthreats.net/t/etpro-feedback/1321)

<div class="topic-metadata">

**Author:** [@countolaf](https://community.emergingthreats.net/u/countolaf)\
**Replies:** 3\
**Last updated:** [January 26, 2024, 9:07pm UTC](https://community.emergingthreats.net/t/etpro-feedback/1321 "2024-01-26T21:07:12Z")

</div>

Hi. Are we allowed to post feedback about FPs for ETPro rules here too? Or should we email feedback@emergingthreats.net? Or another method?

[Next page](https://community.emergingthreats.net/c/feedback-support/8.md?page=1)
