Blog
Recent
May 25, 2010 16:04

Rule release for today, Tuesday May 25th, 2010

A maintenance release, new rules in web-client, web-misc, backdoor, oracle, policy and specific-threats rule sets and an extensive set of rule updates. Check it out: http://www.snort.org/vrt/advisories/2010/05/25/vrt-rules-2010-05-25.html/

May 18, 2010 16:57

Rule release for today, Tuesday May 18th, 2010

Changes to web-client, web-misc, backdoor, smtp and specific-threats rule sets. Check here: http://www.snort.org/vrt/advisories/2010/05/18/vrt-rules-2010-05-18.html for change logs etc..

May 11, 2010 18:31

Rule release for today, Tuesday May 11th, 2010

Microsoft Tuesday folks, just two advisories today and two rules to cover them. Read all about it here: http://www.snort.org/vrt/advisories/2010/05/11/vrt-rules-2010-05-11.html Enjoy.

May 6, 2010 11:46

Known Unknowns: The "Don't Do That" Rules

I recently had a chance to speak with several Sourcefire customers on a trip to the Tennessee/Kentucky area. While it's always nice to talk to customers and get a better idea of how people use Snort in the wild, this trip was particularly interesting, since the customers I sp

April 29, 2010 15:04

Rule release for today, Thursday April 29th, 2010

Performance update release for 2.8.6 to utilize HTTP buffers and fast_pattern. Check here for details.

April 27, 2010 10:56

Using Snort fast patterns wisely for fast rules

Anyone that's ever written their own Snort rule has wondered, at some point or another, about how to make their rule(s) faster. While some things are obvious - don't use a PCRE with a bunch of ".*" clauses, for example - others are less so. Today I'd like to

April 26, 2010 15:44

Rule release for today - April 26th, 2010

This release contains support for Snort 2.8.6.0. Additionally, new packages have been added that contain 4 digit version numbers. New package names: 1. snortrules-snapshot-2853_s.tar.gz 2. snortrules-snapshot-2860_s.tar.gz Details: The packages have been updated with support fo

April 22, 2010 04:34

A New Detection Framework

We just completed a talk here in Dubai on some detection capability research the VRT has been doing.  The subtitle of the presentation, "What would you do with a pointer and a size?" pretty much sums up the potential of the project.  It all started last December at the