|
SIG: TryCloudFlare in SNI
|
|
1
|
112
|
December 10, 2024
|
|
ET TROJAN Win32/BugSleep CnC Checkin
|
|
4
|
403
|
November 2, 2024
|
|
SIGS: Android/TrickMo.Banker
|
|
2
|
89
|
October 29, 2024
|
|
Ailurophile Stealer
|
|
1
|
213
|
October 28, 2024
|
|
Signature Mints Loader
|
|
1
|
122
|
October 25, 2024
|
|
Privateloader
|
|
5
|
403
|
October 14, 2024
|
|
[False Positive] ET INFO domain VirusTotal
|
|
1
|
161
|
October 14, 2024
|
|
PortStarter Backdoor Sigs
|
|
1
|
84
|
October 10, 2024
|
|
Grimresource transformNode Obfuscation
|
|
5
|
199
|
October 10, 2024
|
|
Signature: CleanUp Loader
|
|
2
|
107
|
October 9, 2024
|
|
Sid:2055984 Ivanti Cloud Service Appliance Authenticated Command Injection (CVE-2024-8190)
|
|
1
|
164
|
October 1, 2024
|
|
Poverty Stealer
|
|
12
|
989
|
September 17, 2024
|
|
FP? NanoLocker - SID: 2022331
|
|
1
|
155
|
September 12, 2024
|
|
NMAP ruleset are FP?
|
|
1
|
160
|
September 5, 2024
|
|
DiamotrixClipper
|
|
2
|
340
|
August 30, 2024
|
|
BadSpace Sigs
|
|
1
|
126
|
August 19, 2024
|
|
Where to find details on each threat definition?
|
|
1
|
412
|
August 5, 2024
|
|
Vidar Stealer
|
|
7
|
710
|
July 15, 2024
|
|
Metastealer v.5 TLS
|
|
6
|
554
|
July 10, 2024
|
|
Why not leverage Suricata datasets for IoC rules?
|
|
1
|
177
|
July 8, 2024
|
|
Cryptbot Stealer - Update on Rules
|
|
4
|
641
|
July 5, 2024
|
|
ET POLICY Reserved Internal IP Traffic
|
|
1
|
543
|
June 24, 2024
|
|
False positive on rule #2032926
|
|
4
|
255
|
June 23, 2024
|
|
NjRAT variant - tXRAT v.2.3R
|
|
1
|
228
|
June 21, 2024
|
|
False positives on hunting rule
|
|
2
|
145
|
June 21, 2024
|
|
WhiteSnake
|
|
4
|
346
|
June 17, 2024
|
|
Gh0stRat.Generic SweetSpecter variant
|
|
1
|
309
|
June 13, 2024
|
|
ET EXPLOIT Fortinet FortiSIEM Unauthenticated Command Injection CVE-2023-34992
|
|
3
|
256
|
June 3, 2024
|
|
PrivateLoader Signature
|
|
2
|
188
|
May 20, 2024
|
|
Lumma Stealer Domain
|
|
4
|
243
|
May 20, 2024
|