Does exist somewhere a place where I can read about a particular threat definition ID if I want to know more about?
1 Like
Hey @DVB ,
Welcome to the community and thanks for posting! You can find the descriptions for rules in the SID-Descriptions-ETOpen.json.gz file on our rulesets portal.
Not every rule has a description but we are working to make sure rules going forward have a description added. If there is a specific rule you have questions that is lacking a description or you need additional details always feel free to reach out!
Here are the links for each engine (the descriptions will be the same regardless of engine).
Snort
SID-Descriptions-ETOpen.json.gz
Suricata 4
SID-Descriptions-ETOpen.json.gz
Suricata 5
SID-Descriptions-ETOpen.json.gz
Suricata 7.0.3
SID-Descriptions-ETOpen.json.gz
Thanks,
Isaac
1 Like