Major malware rules update
More in Rules
- Hunting RATs by their own certificates 🕵️
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree:…
- Confusion in WSUS vulnerabilities: setting the record straight
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in…
- Extracting data from disk images with a damaged file system
He may not, as unvalued persons do, Carve for himself (W. Shakespeare) When investigating an infrastructure…
- New connection to old techniques
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered…
- Idea for a correlation rule in SIEM
Idea for a SIEM correlation rule 💡 Although tracking the entire attack chain described in the…
🔄 Major malware rules update Suricata
I hope you remember that we have a public Suricata rules repository (we wrote about launching the resource in another post) and configured suricata-update to support the official rules source ptrules/open?
If anything, here’s a link to the repository.
We don’t live on vulnerabilities and hacktools alone 🙂
We, the network expertise team of the PT ESC antivirus laboratory, have done a lot of work to update the rules aimed at detecting malicious software activity, and now — we’re sharing part of our expertise for public use.
Highlights:
— the RustyNet loader, the WorldWind stealer, the Slam RAT, which we wrote about earlier (in this post, this one, and this one);
— Android malware: SpyNote, Hydra, Zanubis;
— the dreadful XWorm RAT and many other interesting samples.
You can find all the rules on our website.
Malware won’t get through, happy hunting!
#suricata #network #signature #rules
@ptescalator
More in Rules
- Hunting RATs by their own certificates 🕵️
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree:…
- Confusion in WSUS vulnerabilities: setting the record straight
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in…
- Extracting data from disk images with a damaged file system
He may not, as unvalued persons do, Carve for himself (W. Shakespeare) When investigating an infrastructure…
- New connection to old techniques
A New Connection to Old Techniques 📡 During incident investigations, the PT ESC IR team discovered…
- Idea for a correlation rule in SIEM
Idea for a SIEM correlation rule 💡 Although tracking the entire attack chain described in the…






