Ruleset Update Summary - 2024/11/24 - v10749

Summary:

3 new OPEN, 5 new PRO (3 + 2)


Added rules:

Open:

  • 2047755 - ET RETIRED ZenRAT CnC OK Response (retired.rules)
  • 2047757 - ET RETIRED ZenRAT Status Response (retired.rules)
  • 2047762 - ET RETIRED ZenRAT Update CnC Response (Already Actual) (retired.rules)

Pro:

  • 2859130 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M6 (hunting.rules)
  • 2859131 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M7 (hunting.rules)

Modified inactive rules:

  • 2045871 - ET HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M2 (hunting.rules)
  • 2850488 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M1 (hunting.rules)
  • 2850490 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M3 (hunting.rules)
  • 2850491 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M4 (hunting.rules)
  • 2850492 - ETPRO HUNTING JavaScript Engine JIT Forcing Observed - Investigate Possible Exploitation M5 (hunting.rules)

Removed rules:

  • 2047755 - ET MALWARE ZenRAT CnC OK Response (malware.rules)
  • 2047757 - ET MALWARE ZenRAT Status Response (malware.rules)
  • 2047762 - ET MALWARE ZenRAT Update CnC Response (Already Actual) (malware.rules)