|
SIG: TryCloudFlare in SNI
|
|
1
|
109
|
December 10, 2024
|
|
ET TROJAN Win32/BugSleep CnC Checkin
|
|
4
|
399
|
November 2, 2024
|
|
SIGS: Android/TrickMo.Banker
|
|
2
|
84
|
October 29, 2024
|
|
Ailurophile Stealer
|
|
1
|
213
|
October 28, 2024
|
|
Signature Mints Loader
|
|
1
|
119
|
October 25, 2024
|
|
Privateloader
|
|
5
|
399
|
October 14, 2024
|
|
[False Positive] ET INFO domain VirusTotal
|
|
1
|
159
|
October 14, 2024
|
|
PortStarter Backdoor Sigs
|
|
1
|
84
|
October 10, 2024
|
|
Grimresource transformNode Obfuscation
|
|
5
|
199
|
October 10, 2024
|
|
Signature: CleanUp Loader
|
|
2
|
107
|
October 9, 2024
|
|
Sid:2055984 Ivanti Cloud Service Appliance Authenticated Command Injection (CVE-2024-8190)
|
|
1
|
161
|
October 1, 2024
|
|
Poverty Stealer
|
|
12
|
987
|
September 17, 2024
|
|
FP? NanoLocker - SID: 2022331
|
|
1
|
149
|
September 12, 2024
|
|
NMAP ruleset are FP?
|
|
1
|
159
|
September 5, 2024
|
|
DiamotrixClipper
|
|
2
|
338
|
August 30, 2024
|
|
BadSpace Sigs
|
|
1
|
119
|
August 19, 2024
|
|
Where to find details on each threat definition?
|
|
1
|
409
|
August 5, 2024
|
|
Vidar Stealer
|
|
7
|
703
|
July 15, 2024
|
|
Metastealer v.5 TLS
|
|
6
|
549
|
July 10, 2024
|
|
Why not leverage Suricata datasets for IoC rules?
|
|
1
|
175
|
July 8, 2024
|
|
Cryptbot Stealer - Update on Rules
|
|
4
|
639
|
July 5, 2024
|
|
ET POLICY Reserved Internal IP Traffic
|
|
1
|
538
|
June 24, 2024
|
|
False positive on rule #2032926
|
|
4
|
247
|
June 23, 2024
|
|
NjRAT variant - tXRAT v.2.3R
|
|
1
|
228
|
June 21, 2024
|
|
False positives on hunting rule
|
|
2
|
142
|
June 21, 2024
|
|
WhiteSnake
|
|
4
|
346
|
June 17, 2024
|
|
Gh0stRat.Generic SweetSpecter variant
|
|
1
|
307
|
June 13, 2024
|
|
ET EXPLOIT Fortinet FortiSIEM Unauthenticated Command Injection CVE-2023-34992
|
|
3
|
251
|
June 3, 2024
|
|
PrivateLoader Signature
|
|
2
|
185
|
May 20, 2024
|
|
Lumma Stealer Domain
|
|
4
|
240
|
May 20, 2024
|