Where to find details on each threat definition?

Does exist somewhere a place where I can read about a particular threat definition ID if I want to know more about?

1 Like

Hey @DVB ,

Welcome to the community and thanks for posting! You can find the descriptions for rules in the SID-Descriptions-ETOpen.json.gz file on our rulesets portal.

Not every rule has a description but we are working to make sure rules going forward have a description added. If there is a specific rule you have questions that is lacking a description or you need additional details always feel free to reach out!

Here are the links for each engine (the descriptions will be the same regardless of engine).

Snort

SID-Descriptions-ETOpen.json.gz

Suricata 4

SID-Descriptions-ETOpen.json.gz

Suricata 5

SID-Descriptions-ETOpen.json.gz

Suricata 7.0.3

SID-Descriptions-ETOpen.json.gz

Thanks,
Isaac

1 Like