Summary:
3 new OPEN, 5 new PRO (3 + 2)
Added rules:
Open:
- 2047755 - ET RETIRED ZenRAT CnC OK Response (retired.rules)
- 2047757 - ET RETIRED ZenRAT Status Response (retired.rules)
- 2047762 - ET RETIRED ZenRAT Update CnC Response (Already Actual) (retired.rules)
Pro:
- 2859130 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M6 (hunting.rules)
- 2859131 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M7 (hunting.rules)
Modified inactive rules:
- 2045871 - ET HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M2 (hunting.rules)
- 2850488 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M1 (hunting.rules)
- 2850490 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M3 (hunting.rules)
- 2850491 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M4 (hunting.rules)
- 2850492 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M5 (hunting.rules)
Removed rules:
- 2047755 - ET MALWARE ZenRAT CnC OK Response (malware.rules)
- 2047757 - ET MALWARE ZenRAT Status Response (malware.rules)
- 2047762 - ET MALWARE ZenRAT Update CnC Response (Already Actual) (malware.rules)