Ruleset Update Summary - 2023/03/16 - v10270

Summary:

2 new OPEN, 10 new PRO (2 + 8)

The Emerging Threats mailing list is migrating to Discourse. Please visit us at https://community.emergingthreats.net

The mailing list is being retired on April 3, 2023.


Added rules:

Open:

  • 2044665 - ET INFO Outbound SMB NTLM Auth Attempt to External Address (info.rules)
  • 2044666 - ET INFO Outbound SMB Protocol Request to External Address (info.rules)

Pro:

  • 2853726 - ETPRO EXPLOIT Possible Microsoft Outlook Elevation of Privilege Payload Observed M1 (CVE-2023-23397) (exploit.rules)
  • 2853727 - ETPRO EXPLOIT Possible Microsoft Outlook Elevation of Privilege Payload Observed M2 (CVE-2023-23397) (exploit.rules)
  • 2853728 - ETPRO EXPLOIT Possible Microsoft Outlook Elevation of Privilege Payload Observed M3 (CVE-2023-23397) (exploit.rules)
  • 2853729 - ETPRO EXPLOIT Possible Microsoft Outlook Elevation of Privilege Payload Observed M4 (CVE-2023-23397) (exploit.rules)
  • 2853730 - ETPRO EXPLOIT Possible Microsoft Outlook Elevation of Privilege Payload Observed M5 (CVE-2023-23397) (exploit.rules)
  • 2853731 - ETPRO EXPLOIT Possible Microsoft Outlook Elevation of Privilege Payload Observed M6 (CVE-2023-23397) (exploit.rules)
  • 2853732 - ETPRO EXPLOIT Possible Microsoft Outlook Elevation of Privilege Payload Observed M7 (CVE-2023-23397) (exploit.rules)
  • 2853733 - ETPRO EXPLOIT Possible Microsoft Outlook Elevation of Privilege Payload Observed M8 (CVE-2023-23397) (exploit.rules)