# Weekly Community Review - October 27, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-october-27-2023/1072>\
**Category:** Announcements\
**Created:** [October 27, 2023, 5:52pm UTC](https://community.emergingthreats.net/t/weekly-community-review-october-27-2023/1072 "2023-10-27T17:52:20Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [October 27, 2023, 5:52pm UTC](https://community.emergingthreats.net/t/weekly-community-review-october-27-2023/1072/1 "2023-10-27T17:52:20Z")

</div>

Greetings all - we had a short week last week here at @et\_labs - but thanks to shared intel and a treasure trove of shared ICS rules we converted we were able to add 157 (!) rules into our #etopen shared #IDS #suricata and #snort ruleset! That’s amazing. And it’s all free to you!

Thanks to @[nsacyber](https://twitter.com/nsacyber) for making #ELITEWOLF #snort rules available. We’ve converted them to #suricata syntaxes across our supported engines. Be warned - these signatures aren’t necessarily alerting on malicious activity within a #SCADA #ICS network. The overall goal is to help analysts detect anomalous activity originating from unexpected sources. This isn’t about a silver bullet.

> **[GitHub - nsacyber/ELITEWOLF: OT security monitoring #nsacyber](https://github.com/nsacyber/ELITEWOLF)**
>
> OT security monitoring #nsacyber. Contribute to nsacyber/ELITEWOLF development by creating an account on GitHub.

After observing alerts firing in your environment, analysts will need to invest time to determine whether these rules represent anomalous activities. #IDS #IPS #NSM operators may need to utilize methods to reduce alerts for legitimate Industrial Control System traffic such as Suppressions, Thresholds, pass rules, and modifying the rule header to more accurately reflect “external” hosts attempting to access ICS assets to gain more value out of these rules. Alerts are the beginning of an investigation - not the end!

Thanks go to @[g0njxa](https://twitter.com/g0njxa) for their #FakeUpdate landing pages - SIDs 2048570-2048576 cover the landing page DNS queries and TLS SNI connections.

> <https://twitter.com/g0njxa/status/1713919587996057847>

Speaking of #FakeBrowserUpdates - check out our own @dumiller here on the Five-Minute Forecast. He takes about the malicious URL lures and the malicious payload download!

> **[Five-Minute Forecast for the Week of 10/23/2023](https://www.spreaker.com/user/16860719/5mf102323)**
>
> Five Minute Forecast for the week of October 23rd. All the cyber security news you need to stay ahead, from Proofpoint’s Protecting People podcast.
> • ICC hit by cyber espionage amid sensitive trials
> • Spanish police bust phishing ring that...

A couple #RAT SIDs 2048661 (C2 activity) and 2048662 (host checkin) from this @[reecdeep](https://twitter.com/reecdeep) tweet which allowed us to hotel the GET strings for accurate alerting!

> <https://twitter.com/reecdeep/status/1715053326859895210>
>
> 0xToxin🕷️ @0xToxin

This @[TalosSecurity](https://twitter.com/TalosSecurity) technical writeup of their #CVE-2023-20198 disclosure aided two SIDs we created for detection of the interactive implants (2048583-2048584) left behind on compromised devices for later malicious activity. In total, we’ve got multiple detections in place - including inbound and outbound implant checks and implant responses.

> **[Active exploitation of Cisco IOS XE Software Web Management User Interface...](https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/)**
>
> Cisco has identified active exploitation of two previously unknown vulnerabilities in the Web User Interface (Web UI) feature of Cisco IOS XE software - CVE-2023-20198 and CVE-2023-20273 - when exposed to the internet or untrusted networks.

This @[RecordedFuture](https://twitter.com/RecordedFuture) tweet and subsequent linked report contained multiple #IOC intel that led to SIDs 2048695-2048702 #TA401 DNS query and TLS connection detections!

> <https://twitter.com/RecordedFuture/status/1715050356718133564?s=20>

That’s it for us all - be safe and well this week!
