# Wiki

**URL:** https://community.emergingthreats.net/c/wiki/6.md

[Latest](https://community.emergingthreats.net/latest.md) · [Categories](https://community.emergingthreats.net/categories.md) · [Tags](https://community.emergingthreats.net/tags.md)

---

## [About the Wiki category](https://community.emergingthreats.net/t/about-the-wiki-category/22)

<div class="topic-metadata">

**Author:** [@dkaczmark](https://community.emergingthreats.net/u/dkaczmark)\
**Replies:** 0

</div>

How the ET Team works - Rule Creation, Supported Engine Lifecycle, QA Process and more.

---

## [Suricata 5, 6, & 7 Rule Categories](https://community.emergingthreats.net/t/suricata-5-6-7-rule-categories/94)

<div class="topic-metadata">

**Author:** [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Replies:** 0\
**Last updated:** [October 14, 2022, 11:13pm UTC](https://community.emergingthreats.net/t/suricata-5-6-7-rule-categories/94 "2022-10-14T23:13:47Z")

</div>

ET features over 50 categories which may be assigned to individual signatures. These categories are assigned as signatures are created and updated. To help understand how these category names are selected and attributed…

---

## [Rule Performance and QA](https://community.emergingthreats.net/t/rule-performance-and-qa/3020)

<div class="topic-metadata">

**Author:** [@wim](https://community.emergingthreats.net/u/wim)\
**Replies:** 0\
**Last updated:** [September 9, 2025, 1:47pm UTC](https://community.emergingthreats.net/t/rule-performance-and-qa/3020 "2025-09-09T13:47:06Z")

</div>

Hi :slight\_smile: Measuring Suricata’s performance — and testing rules for optimization — is often a grueling process. Anyone who’s tried it has probably found themselves asking: “Why am I seeing 200k checks before MPM …

---

## [Signature ID Allocation Ranges](https://community.emergingthreats.net/t/signature-id-allocation-ranges/491)

<div class="topic-metadata">

**Author:** [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Replies:** 0\
**Last updated:** [April 19, 2023, 7:18pm UTC](https://community.emergingthreats.net/t/signature-id-allocation-ranges/491 "2023-04-19T19:18:28Z")

</div>

For assignation of SIDs for both bespoke/curated daily signatures as well as our automated offerings which are based on third-party sources, the ET team follows the guidance built from a contribution of a number of Indus…

---

## [CyberSecure by Proofpoint and Cloudflare - Unifi Intrusion Prevention](https://community.emergingthreats.net/t/cybersecure-by-proofpoint-and-cloudflare-unifi-intrusion-prevention/2905)

<div class="topic-metadata">

**Author:** [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Replies:** 0\
**Last updated:** [July 17, 2025, 8:48pm UTC](https://community.emergingthreats.net/t/cybersecure-by-proofpoint-and-cloudflare-unifi-intrusion-prevention/2905 "2025-07-17T20:48:56Z")

</div>

Introduction: CyberSecure is a service that is available on several Ubiquiti Unifi appliances including the Cloud Gateway devices which are popular within SOHO environments. CyberSecure consists of multiple detection met…

---

## [Supported Engines](https://community.emergingthreats.net/t/supported-engines/71)

<div class="topic-metadata">

**Author:** [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Replies:** 0\
**Last updated:** [October 5, 2022, 7:30pm UTC](https://community.emergingthreats.net/t/supported-engines/71 "2022-10-05T19:30:28Z")

</div>

Currently the ET Open and ETPRO rulesets are released for the following supported engines: Suricata Suricata 7.0.3 (and greater sub-versions) Suricata 6.0.x (leverages Suricata 5 ruleset) Suricata 5.0.x Snort 2.9.1…

---

## [The new compromised\_website metadata tag](https://community.emergingthreats.net/t/the-new-compromised-website-metadata-tag/2001)

<div class="topic-metadata">

**Author:** [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Replies:** 0\
**Last updated:** [September 23, 2024, 9:12pm UTC](https://community.emergingthreats.net/t/the-new-compromised-website-metadata-tag/2001 "2024-09-23T21:12:16Z")

</div>

Greetings! You may have noticed we recently introduced a new metadata tag to several rules (in fact, over 1700) - ‘compromised\_website’. This tag indicates a rule is alerting on the threat actor tactic of using malicio…

---

## [Signature Metadata](https://community.emergingthreats.net/t/signature-metadata/96)

<div class="topic-metadata">

**Author:** [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Replies:** 0\
**Last updated:** [October 17, 2022, 7:33pm UTC](https://community.emergingthreats.net/t/signature-metadata/96 "2022-10-17T19:33:15Z")

</div>

Metadata Tag Use Cases: Metadata tags in the ET ruleset provide useful information for network security operators around the purpose, classification, and context of given signatures. There are two primary use cases for…

---

## [Rule States and Support Tiers](https://community.emergingthreats.net/t/rule-states-and-support-tiers/1789)

<div class="topic-metadata">

**Author:** [@bingohotdog](https://community.emergingthreats.net/u/bingohotdog)\
**Replies:** 0\
**Last updated:** [July 1, 2024, 11:12pm UTC](https://community.emergingthreats.net/t/rule-states-and-support-tiers/1789 "2024-07-01T23:12:24Z")

</div>

UPDATES: Added updateCategory() event to reflect how rules change switch between RETIRED and DELETED categories. This post explores the nuances behind a rule’s enabled or disabled state AND its implied support tier. T…

---

## [Frequently Asked Questions](https://community.emergingthreats.net/t/frequently-asked-questions/56)

<div class="topic-metadata">

**Author:** [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Replies:** 0\
**Last updated:** [September 26, 2022, 7:58pm UTC](https://community.emergingthreats.net/t/frequently-asked-questions/56 "2022-09-26T19:58:43Z")

</div>

What is Emerging Threats? Emerging Threats is a division of Proofpoint, Inc. Our primary projects are the Emerging Threats Ruleset, contributed and maintained by the security community, and the Emerging Threats Pro Rules…

---

## [Moving a signature from Pro to Open](https://community.emergingthreats.net/t/moving-a-signature-from-pro-to-open/1026)

<div class="topic-metadata">

**Author:** [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Replies:** 0\
**Last updated:** [October 11, 2023, 4:17pm UTC](https://community.emergingthreats.net/t/moving-a-signature-from-pro-to-open/1026 "2023-10-11T16:17:03Z")

</div>

Any ETPRO signature has the potential of being moved to the free ET Open ruleset. This can happen, for example, if a user submits a signatures which has original coverage for an ETPRO signature. In cases like that the…

---

## [Suricata 7 Keyword Updates from Suricata 5](https://community.emergingthreats.net/t/suricata-7-keyword-updates-from-suricata-5/1013)

<div class="topic-metadata">

**Author:** [@jtaylor](https://community.emergingthreats.net/u/jtaylor)\
**Replies:** 0\
**Last updated:** [October 5, 2023, 9:37pm UTC](https://community.emergingthreats.net/t/suricata-7-keyword-updates-from-suricata-5/1013 "2023-10-05T21:37:17Z")

</div>

Emerging Threats will be adding a Suricata 7 fork which will allow us to make more efficient rules using the latest available keywords and keyword options. We wanted to pass along some of the changes between versions so …

---

## [Handling IOC Based Rules with TLS Decryption](https://community.emergingthreats.net/t/handling-ioc-based-rules-with-tls-decryption/948)

<div class="topic-metadata">

**Author:** [@bmurphy](https://community.emergingthreats.net/u/bmurphy)\
**Replies:** 0\
**Last updated:** [September 15, 2023, 12:13am UTC](https://community.emergingthreats.net/t/handling-ioc-based-rules-with-tls-decryption/948 "2023-09-15T00:13:03Z")

</div>

A customer recently requested details on how Emerging Threats ensures coverage of rules which leverage TLS keywords for environments which have TLS decryption in place. This specific environment involves the TLS decrypti…

---

## [New metadata tag - reviewed\_at](https://community.emergingthreats.net/t/new-metadata-tag-reviewed-at/881)

<div class="topic-metadata">

**Author:** [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Replies:** 0\
**Last updated:** [August 21, 2023, 9:47pm UTC](https://community.emergingthreats.net/t/new-metadata-tag-reviewed-at/881 "2023-08-21T21:47:46Z")

</div>

Starting last week we started pushing a new metadata field to rules in the ruleset: reviewed\_at. This tag will indicate the date the ET team reviewed the rule last as part of our continuous improvement processes. If a …

---

## [Confidence metadata tag and its impact & meaning](https://community.emergingthreats.net/t/confidence-metadata-tag-and-its-impact-meaning/343)

<div class="topic-metadata">

**Author:** [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Replies:** 0\
**Last updated:** [March 4, 2023, 12:48am UTC](https://community.emergingthreats.net/t/confidence-metadata-tag-and-its-impact-meaning/343 "2023-03-04T00:48:37Z")

</div>

Taken from a great feedback interaction from one of our users, I thought I’d share @bmurphy’s response on the Confidence metadata tag we’ve recently introduced. The user asked after whether the tag contents meant whethe…

---

## [Rules Severities](https://community.emergingthreats.net/t/rules-severities/337)

<div class="topic-metadata">

**Author:** [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Replies:** 0\
**Last updated:** [February 28, 2023, 10:17pm UTC](https://community.emergingthreats.net/t/rules-severities/337 "2023-02-28T22:17:48Z")

</div>

A reminder for ET rule severity: o Informational: This is a signature meant to detect activity which may not be malicious in and of itself, but useful to record to add context to other events or alerts. It is often…
