Talos has added and modified multiple rules in the file-image, file-other, malware-other and server-webapp rule sets to provide coverage for emerging threats from these technologies.
For information about Snort Subscriber Rulesets available for purchase, please visit the Snort product page.
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2092000.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:66123 <-> DISABLED <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt (server-webapp.rules) * 1:66124 <-> ENABLED <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt (malware-other.rules) * 1:66125 <-> ENABLED <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt (malware-other.rules) * 1:66126 <-> DISABLED <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt (server-webapp.rules) * 1:66127 <-> DISABLED <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt (file-other.rules) * 1:66128 <-> DISABLED <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt (file-other.rules) * 1:66129 <-> DISABLED <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt (server-samba.rules) * 1:66130 <-> DISABLED <-> SERVER-SAMBA Samba WINS hook query name command injection attempt (server-samba.rules) * 1:66135 <-> ENABLED <-> SERVER-WEBAPP n8n workflows remote code execution attempt (server-webapp.rules) * 1:66136 <-> ENABLED <-> SERVER-WEBAPP n8n workflows remote code execution attempt (server-webapp.rules) * 1:66137 <-> DISABLED <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt (server-webapp.rules) * 1:66138 <-> DISABLED <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt (server-webapp.rules) * 1:66139 <-> DISABLED <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt (server-webapp.rules) * 3:66131 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66132 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66133 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66134 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66140 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt (server-webapp.rules) * 3:66141 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt (server-webapp.rules) * 3:66142 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt (server-webapp.rules)
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091801.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:66127 <-> DISABLED <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt (file-other.rules) * 1:66135 <-> ENABLED <-> SERVER-WEBAPP n8n workflows remote code execution attempt (server-webapp.rules) * 1:66136 <-> ENABLED <-> SERVER-WEBAPP n8n workflows remote code execution attempt (server-webapp.rules) * 1:66139 <-> DISABLED <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt (server-webapp.rules) * 1:66123 <-> DISABLED <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt (server-webapp.rules) * 1:66124 <-> ENABLED <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt (malware-other.rules) * 1:66128 <-> DISABLED <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt (file-other.rules) * 1:66130 <-> DISABLED <-> SERVER-SAMBA Samba WINS hook query name command injection attempt (server-samba.rules) * 1:66125 <-> ENABLED <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt (malware-other.rules) * 1:66126 <-> DISABLED <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt (server-webapp.rules) * 1:66137 <-> DISABLED <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt (server-webapp.rules) * 1:66138 <-> DISABLED <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt (server-webapp.rules) * 1:66129 <-> DISABLED <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt (server-samba.rules) * 3:66131 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66132 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66133 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66134 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66140 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt (server-webapp.rules) * 3:66141 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt (server-webapp.rules) * 3:66142 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt (server-webapp.rules)
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091701.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:66125 <-> ENABLED <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt (malware-other.rules) * 1:66137 <-> DISABLED <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt (server-webapp.rules) * 1:66136 <-> ENABLED <-> SERVER-WEBAPP n8n workflows remote code execution attempt (server-webapp.rules) * 1:66124 <-> ENABLED <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt (malware-other.rules) * 1:66129 <-> DISABLED <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt (server-samba.rules) * 1:66130 <-> DISABLED <-> SERVER-SAMBA Samba WINS hook query name command injection attempt (server-samba.rules) * 1:66127 <-> DISABLED <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt (file-other.rules) * 1:66128 <-> DISABLED <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt (file-other.rules) * 1:66138 <-> DISABLED <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt (server-webapp.rules) * 1:66139 <-> DISABLED <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt (server-webapp.rules) * 1:66123 <-> DISABLED <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt (server-webapp.rules) * 1:66126 <-> DISABLED <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt (server-webapp.rules) * 1:66135 <-> ENABLED <-> SERVER-WEBAPP n8n workflows remote code execution attempt (server-webapp.rules) * 3:66131 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66132 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66133 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66134 <-> ENABLED <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt (file-image.rules) * 3:66140 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt (server-webapp.rules) * 3:66141 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt (server-webapp.rules) * 3:66142 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt (server-webapp.rules)
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.2.0.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.3.5.1.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.3.6.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.3.7.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.7.0.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.9.0.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.11.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.15.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.18.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.12.0.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.21.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.35.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.44.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.47.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.11.0.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.12.0.0.
The format of the file is:
gid:sid <-> Message
* 1:301449 <-> SERVER-OTHER OpenLDAP ber_get_next denial of service attempt * 1:301450 <-> MALWARE-OTHER Win.Trojan.UltiEr download attempt * 1:301451 <-> FILE-OTHER CodeFuse ModelCache unsafe deserialization remote code execution attempt * 1:301452 <-> SERVER-OTHER Squid Proxy HTTP chunked extension denial of service attempt * 1:301453 <-> SERVER-WEBAPP Tenda AC1200 formSetMacFilterCfg buffer overflow attempt * 1:66123 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 1:66126 <-> SERVER-WEBAPP Progress WhatsUp Gold arbitrary file upload attempt * 1:66129 <-> SERVER-SAMBA Samba WINS hook additional record command injection attempt * 1:66130 <-> SERVER-SAMBA Samba WINS hook query name command injection attempt * 1:66135 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66136 <-> SERVER-WEBAPP n8n workflows remote code execution attempt * 1:66139 <-> SERVER-WEBAPP SolarWinds Orion Patch Manager insecure deserialization attempt * 3:66131 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66132 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66133 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66134 <-> FILE-IMAGE TRUFFLEHUNTER TALOS-2026-2330 attack attempt * 3:66140 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2348 attack attempt * 3:66141 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2349 attack attempt * 3:66142 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2355 attack attempt