Ruleset Update Summary - 2024/12/01 - v10775

Summary:

0 new OPEN, 0 new PRO (0 + 0)


Modified inactive rules:

  • 2035396 - ET HUNTING Multiple User-Agent Components in a single UA (hunting.rules)
  • 2044228 - ET HUNTING Observed Meterpreter Style Request (GET) (hunting.rules)
  • 2044538 - ET HUNTING robots Request (set) (hunting.rules)
  • 2045047 - ET HUNTING Gamaredon APT Style Request (GET) (hunting.rules)
  • 2851305 - ETPRO HUNTING Suspicious User-Agent - No space after Mozilla version (hunting.rules)
  • 2853060 - ETPRO HUNTING Possible PowerShell Inbound - Casing Anomaly (Replace) M1 (hunting.rules)
  • 2853062 - ETPRO HUNTING Possible PowerShell Inbound - Casing Anomaly (StringChar) M1 (hunting.rules)
  • 2853567 - ETPRO HUNTING Suspicious Empty Critical-CH Header (hunting.rules)
  • 2855498 - ETPRO MALWARE Possible DarkGate AutoIT Script Download (malware.rules)