Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Snort POLICY PE EXE or DLL Windows file download alert

    Scheduled Pinned Locked Moved pfSense Packages
    2 Posts 2 Posters 15.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      wbennett77
      last edited by

      Howdy folks,

      Getting a lot of ET POLICY PE EXE or DLL Windows file download alerts and being a newbie not sure what this is. I have noticed that whatever it is is trying many ports. Any guidance or advice would be appreciated.

      Thanks!

      Dell Optiplex 390 Pfsense 2.2 / Asus AC56U Wireless AP / Asus Switch

      1 Reply Last reply Reply Quote 0
      • F
        firewalluser
        last edited by

        In the alerts page, find the policy and click the suppress icon to add a suppress rule to the interface.

        You can find the surpress rule in the Services, Snort, Suppress tab, where you will see one or more entries like so
        wansuppress_5437e6139435f
        lansuppress_544229bb9e947

        In side the suppress rule you will see something like
        #ET POLICY PE EXE or DLL Windows file download
        suppress gen_id 1, sig_id 2000419

        This is your basic suppress rule which will not block any Windows PE file. PE is just the name given to the format of the windows exe and dll's.  http://en.wikipedia.org/wiki/Portable_Executable

        You can also tweak the rules a bit to suit your needs better.

        These threads might be useful.
        https://forum.pfsense.org/index.php?topic=61018.msg339645#msg339645
        https://forum.pfsense.org/index.php/topic,62928.msg341417.html#msg341417

        Capitalism, currently The World's best Entertainment Control System and YOU cant buy it! But you can buy this, or some of this or some of these

        Asch Conformity, mainly the blind leading the blind.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.