Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Important Emerging Threats Rules False Positive Announcement

    Scheduled Pinned Locked Moved IDS/IPS
    1 Posts 1 Posters 354 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bmeeksB
      bmeeks
      last edited by

      Saw this post first over on the Suricata.io forum and then followed it to its source here: https://github.com/EmergingThreats/threatresearch/blob/master/announcements/2022-07-19/README.md.

      The short version is the Emerging Threats Team (a.k.a. ProofPoint) released an update for two of their DNS anomaly rules (2014702 and 2014703) on July 15, 2022. The updates contained an error that resulted in a high level of false positives from the two rules. The change was backed out in the rules update published July 18, 2022.

      1 Reply Last reply Reply Quote 3
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.