Important Emerging Threats Rules False Positive Announcement
-
Saw this post first over on the Suricata.io forum and then followed it to its source here: https://github.com/EmergingThreats/threatresearch/blob/master/announcements/2022-07-19/README.md.
The short version is the Emerging Threats Team (a.k.a. ProofPoint) released an update for two of their DNS anomaly rules (2014702 and 2014703) on July 15, 2022. The updates contained an error that resulted in a high level of false positives from the two rules. The change was backed out in the rules update published July 18, 2022.