<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Drop rule question]]></title><description><![CDATA[<p dir="auto">I just would like to ask if this is how dropsid syntax is to be done.</p>
<p dir="auto">emerging-attack_response,emerging-botcc.portgrouped,emerging-botcc,emerging-compromised,emerging-dos,emerging-dshield,emerging-exploit,emerging-malware,emerging-misc,emerging-mobile_malware,emerging-p2p,emerging-tor,emerging-trojan,emerging-worm,snort_backdoor,snort_botnet-cnc,snort_ddos,snort_dos,snort_malware-backdoor,snort_malware-cnc,snort_malware-other,snort_malware-tools,snort_misc,snort_p2p,snort_pua-p2p,snort_specific-threats,snort_spyware-put,snort_virus,GPLv2_community</p>
<p dir="auto">I placed the above rule on dropsid-sample.conf and selected it on Drop SID File.  Suricata detected and have an alert on ET TROJAN  downadup/Conficker A or B Worm reporting, however, it is not dropping it since the highlight is not in red color.</p>
]]></description><link>https://forum.netgate.com/topic/104865/drop-rule-question</link><generator>RSS for Node</generator><lastBuildDate>Fri, 14 Aug 2026 04:11:03 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/104865.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 01 Sep 2016 06:27:49 GMT</pubDate><ttl>60</ttl></channel></rss>