New IPS rule category showed up

I noticed a new Suricata rule
on the bottom of the ET Community ruleset

threatview_CS_c2.rules

The category was UNchecked, if you click “show”
it shows the following rules

2 Likes

Thank you for the hint, activated on my box!

1 Like

Hi,

yes, the Emerging Threat folks seem to do that by default.

It is a wise decision, since one size never fits all. While these rules should not generate any false positive or other harm, they might be unwanted or unnecessary in some scenarios (such as internal networks without any internet connectivity).

Therefore, it is a good idea to check for new IPS rule categories every now and then. :slight_smile:

Thanks, and best regards,
Peter Müller

3 Likes

FYI:
Running “Talos VRT rules with subscription”,
I could not identify them in today’s
. . . . . ## Ruleset (2022-02-10 01:25:40)
yet.

1 Like