]> git.ipfire.org Git - thirdparty/suricata-intel-index.git/log
thirdparty/suricata-intel-index.git
16 months agonmap: add nmap ruleset 28/head
Sascha Steinbiss [Mon, 1 Jul 2024 19:42:26 +0000 (21:42 +0200)] 
nmap: add nmap ruleset

17 months agoruleset: add ptrules open 27/head
cloffyn [Sun, 15 Sep 2024 23:54:13 +0000 (05:54 +0600)] 
ruleset: add ptrules open

18 months agoci: add validation action
Sascha Steinbiss [Mon, 1 Jul 2024 10:47:37 +0000 (12:47 +0200)] 
ci: add validation action

18 months agoversion: remove 6.0 25/head
Shivani Bhardwaj [Mon, 12 Aug 2024 05:57:38 +0000 (11:27 +0530)] 
version: remove 6.0

19 months agoversion: update to 7.0.6 and 6.0.20
Victor Julien [Thu, 27 Jun 2024 09:45:26 +0000 (11:45 +0200)] 
version: update to 7.0.6 and 6.0.20

21 months agoruleset: add abuse.ch urlhaus ruleset 20/head
Jason Ish [Thu, 9 May 2024 22:02:05 +0000 (16:02 -0600)] 
ruleset: add abuse.ch urlhaus ruleset

21 months agoruleset: abuse.ch/feodotracker
Jason Ish [Thu, 9 May 2024 19:23:59 +0000 (13:23 -0600)] 
ruleset: abuse.ch/feodotracker

Add the Abuse.ch Feodo Tracker C2 IP ruleset.

21 months agoruleset: abuse.ch botnet c2 ip ruleset
Jason Ish [Wed, 8 May 2024 23:27:34 +0000 (17:27 -0600)] 
ruleset: abuse.ch botnet c2 ip ruleset

Add the Abuse.ch BotNet C2 IP ruleset

21 months agosslbl: deprecated in favor of new abuse.ch namespace
Jason Ish [Wed, 8 May 2024 23:23:37 +0000 (17:23 -0600)] 
sslbl: deprecated in favor of new abuse.ch namespace

Put the SSLBL rulesets under the abuse.ch namespace and mark the
previous ones as deprecated.

21 months agosslbl/ja3-fingerprints: use .tar.gz URL
Jason Ish [Wed, 8 May 2024 23:14:08 +0000 (17:14 -0600)] 
sslbl/ja3-fingerprints: use .tar.gz URL

Saves a bit of bandwidth.

21 months agosslbl/blacklist: update to more modern URL
Jason Ish [Wed, 8 May 2024 23:13:05 +0000 (17:13 -0600)] 
sslbl/blacklist: update to more modern URL

Uses Suricata 4.1 features.

21 months agosslbl: update license to CC0 (CC0-1.0)
Jason Ish [Wed, 8 May 2024 23:10:15 +0000 (17:10 -0600)] 
sslbl: update license to CC0 (CC0-1.0)

Thanks @voteblake: https://github.com/OISF/suricata-update/pull/336

21 months agopawpatrules: min-version of 7.0.3
Jason Ish [Thu, 2 May 2024 17:54:35 +0000 (11:54 -0600)] 
pawpatrules: min-version of 7.0.3

Pawpatrules is now using the "requires" keyword to make use of some 8.0
features.

21 months agotgreen/hunting: update to use .tar.gz url
Jason Ish [Mon, 22 Apr 2024 23:16:53 +0000 (17:16 -0600)] 
tgreen/hunting: update to use .tar.gz url

The .tar.gz contains the file timestamp which are useul. The previous
raw file URL did not have any time info as GitHub does not provide a
last-modified header.

21 months agoversion: update to 7.0.5 and 6.0.19
Victor Julien [Tue, 23 Apr 2024 12:15:46 +0000 (14:15 +0200)] 
version: update to 7.0.5 and 6.0.19

23 months agoversion: update 6.0.18
Shivani Bhardwaj [Thu, 21 Mar 2024 06:33:37 +0000 (12:03 +0530)] 
version: update 6.0.18

23 months agoversion: update to 7.0.4 and 6.0.17
Victor Julien [Tue, 19 Mar 2024 16:40:37 +0000 (17:40 +0100)] 
version: update to 7.0.4 and 6.0.17

2 years agonew ruleset: pawpatrules 16/head
Jason Ish [Wed, 1 Nov 2023 20:33:23 +0000 (14:33 -0600)] 
new ruleset: pawpatrules

2 years agoversion: update 7.0.3
Shivani Bhardwaj [Thu, 8 Feb 2024 09:13:31 +0000 (14:43 +0530)] 
version: update 7.0.3

2 years agoversion: update 6.0.16
Shivani Bhardwaj [Thu, 8 Feb 2024 09:07:19 +0000 (14:37 +0530)] 
version: update 6.0.16

2 years agoruleset: add Stamus NRD rulesets
Eric Leblond [Wed, 18 Oct 2023 09:10:52 +0000 (11:10 +0200)] 
ruleset: add Stamus NRD rulesets

2 years agoversion: update 7.0.2 and 6.0.15
Victor Julien [Thu, 19 Oct 2023 12:17:41 +0000 (14:17 +0200)] 
version: update 7.0.2 and 6.0.15

2 years agoversion: update 7.0.1
Victor Julien [Thu, 14 Sep 2023 13:53:06 +0000 (15:53 +0200)] 
version: update 7.0.1

2 years agoversion: update 6.0.14
Juliana Fajardini [Wed, 13 Sep 2023 14:18:47 +0000 (11:18 -0300)] 
version: update 6.0.14

2 years agoversion: update 7.0.0
Shivani Bhardwaj [Tue, 18 Jul 2023 04:36:11 +0000 (10:06 +0530)] 
version: update 7.0.0

2 years agoversion: update 6.0.13
Shivani Bhardwaj [Thu, 15 Jun 2023 03:15:54 +0000 (08:45 +0530)] 
version: update 6.0.13

2 years agoversion: update 6.0.12
Shivani Bhardwaj [Mon, 8 May 2023 09:24:16 +0000 (14:54 +0530)] 
version: update 6.0.12

2 years agoversion: update to 6.0.11
Jason Ish [Thu, 13 Apr 2023 18:20:07 +0000 (12:20 -0600)] 
version: update to 6.0.11

3 years agoversion: update 6.0.10
Shivani Bhardwaj [Tue, 31 Jan 2023 06:19:04 +0000 (11:49 +0530)] 
version: update 6.0.10

3 years agoversion: update 6.0.9
Victor Julien [Mon, 28 Nov 2022 06:18:03 +0000 (07:18 +0100)] 
version: update 6.0.9

3 years agoruleset: Stamus Networks lateral movement 13/head
Jason Ish [Sun, 13 Nov 2022 15:35:28 +0000 (08:35 -0700)] 
ruleset: Stamus Networks lateral movement

3 years agoversions: 6.0.8; remove 5.0
Jason Ish [Sun, 13 Nov 2022 15:12:58 +0000 (08:12 -0700)] 
versions: 6.0.8; remove 5.0

3 years agoversion: update 6.0.7
Shivani Bhardwaj [Tue, 27 Sep 2022 10:08:49 +0000 (15:38 +0530)] 
version: update 6.0.7

3 years agoversions: 5.0.10 and 6.0.6
Jason Ish [Wed, 13 Jul 2022 17:52:12 +0000 (11:52 -0600)] 
versions: 5.0.10 and 6.0.6

3 years agoversions: 5.0.9 and 6.0.5
Jason Ish [Thu, 21 Apr 2022 13:48:00 +0000 (07:48 -0600)] 
versions: 5.0.9 and 6.0.5

3 years agoptresearch: mark as obsolete. 12/head
Jason Ish [Thu, 14 Apr 2022 15:43:35 +0000 (09:43 -0600)] 
ptresearch: mark as obsolete.

This ruleset is gone from GitHub. Mark it as obsolete so Suricata-Update
will stop trying to download it.

4 years agoversions: update for 6.0.4, 5.0.8
Victor Julien [Thu, 18 Nov 2021 15:01:19 +0000 (16:01 +0100)] 
versions: update for 6.0.4, 5.0.8

4 years agoRemove special quote char: causes issues with Python 2
Jason Ish [Thu, 28 Oct 2021 15:15:05 +0000 (09:15 -0600)] 
Remove special quote char: causes issues with Python 2

A unicode single quote has started to trip up Python 2. Removing
replacing this special quote is the easiest way to deal with it
for now.

4 years agomalsilo: update home page
Jason Ish [Fri, 8 Oct 2021 21:42:03 +0000 (15:42 -0600)] 
malsilo: update home page

4 years agomalsilo: add homepage, has checksum url
Jason Ish [Fri, 8 Oct 2021 15:11:15 +0000 (09:11 -0600)] 
malsilo: add homepage, has checksum url

4 years agonew source: MalSilo ip, dns and url rules sources
raw-data [Mon, 1 Jun 2020 13:47:39 +0000 (14:47 +0100)] 
new source: MalSilo ip, dns and url rules sources

4 years agoversions: update for 6.0.3, 5.0.7.
Jason Ish [Wed, 30 Jun 2021 15:54:41 +0000 (09:54 -0600)] 
versions: update for 6.0.3, 5.0.7.

4 years agoversions: update for 6.0.2, 5.0.6. 4.1 is EOL
Victor Julien [Tue, 2 Mar 2021 10:16:29 +0000 (11:16 +0100)] 
versions: update for 6.0.2, 5.0.6. 4.1 is EOL

5 years agoversions: update for 6.0.1, 5.0.5 and 4.1.10 releases
Jason Ish [Fri, 4 Dec 2020 14:30:59 +0000 (08:30 -0600)] 
versions: update for 6.0.1, 5.0.5 and 4.1.10 releases

5 years agoversions: update for 6.0.0/5.0.4/4.1.9 releases
Victor Julien [Thu, 8 Oct 2020 13:30:45 +0000 (15:30 +0200)] 
versions: update for 6.0.0/5.0.4/4.1.9 releases

5 years agoversions: update for 4.1.8/5.0.3 releases
Victor Julien [Tue, 28 Apr 2020 12:44:25 +0000 (14:44 +0200)] 
versions: update for 4.1.8/5.0.3 releases

6 years agoversions: update for 4.1.7/5.0.2 releases
Victor Julien [Thu, 13 Feb 2020 16:00:17 +0000 (17:00 +0100)] 
versions: update for 4.1.7/5.0.2 releases

6 years agoNew index: scwx/enhanced
counterthreatunit [Fri, 6 Dec 2019 02:46:03 +0000 (21:46 -0500)] 
New index: scwx/enhanced

Also updated min-version on the ther SCWX rulesets.

6 years agoversions: update
Jason Ish [Fri, 13 Dec 2019 15:01:13 +0000 (09:01 -0600)] 
versions: update

Recommended is now 5.0.1.
Current 5.0 is now 5.0.1.
Current 4.1 is now 4.1.6.

6 years agoversions: Suricata 5.0.0
Jason Ish [Tue, 15 Oct 2019 14:59:48 +0000 (08:59 -0600)] 
versions: Suricata 5.0.0

6 years agoversions: suricata 4.1 and recomended is now 4.1.5 6/head
Jason Ish [Fri, 11 Oct 2019 14:35:14 +0000 (08:35 -0600)] 
versions: suricata 4.1 and recomended is now 4.1.5

6 years agochecksum: use checksum: true|false instead of no-checksum 5/head
Jason Ish [Thu, 5 Sep 2019 15:13:06 +0000 (09:13 -0600)] 
checksum: use checksum: true|false instead of no-checksum

Currently Suricata-Update still assumes a checksum exists, and
is an md5 checksum. This can be set to false to indicate there
is not a checksum-url.

6 years agoAdd no-checksum to index
Vagisha Gupta [Tue, 27 Aug 2019 16:11:22 +0000 (21:41 +0530)] 
Add no-checksum to index

Added `no-checksum` to the suricata-intel-index for the sources
which have MD5 files.

6 years agoAdd suricata version info to index
Vagisha Gupta [Wed, 10 Jul 2019 09:17:17 +0000 (14:47 +0530)] 
Add suricata version info to index

The recommended and supported version info for suricata is made
part of the index.

6 years agocleanup: remove trailing whitespace
Jason Ish [Fri, 26 Apr 2019 21:10:09 +0000 (15:10 -0600)] 
cleanup: remove trailing whitespace

6 years agoUpdate and cleanup 1/head
Travis Green [Thu, 25 Apr 2019 20:12:42 +0000 (14:12 -0600)] 
Update and cleanup

Ordered keynames more consistantly. Added JA3 ruleset from abuse.ch.
Shortened tgreen rules summary to < 100 chars, added description.

6 years agooisf/trafficid: update url to oisf hosted rules
Jason Ish [Wed, 24 Apr 2019 05:10:13 +0000 (23:10 -0600)] 
oisf/trafficid: update url to oisf hosted rules

7 years agoAdd tgreen/hunting rule source
Travis Green [Thu, 15 Nov 2018 23:16:37 +0000 (16:16 -0700)] 
Add tgreen/hunting rule source

7 years agoNew source: Etnetera aggressive IP blacklist
Jason Ish [Fri, 14 Sep 2018 04:49:37 +0000 (22:49 -0600)] 
New source: Etnetera aggressive IP blacklist

8 years agosecurework: subscribe url
Jason Ish [Tue, 16 Jan 2018 22:48:00 +0000 (16:48 -0600)] 
securework: subscribe url

8 years agoAdd Secureworks rulesets.
Jason Ish [Tue, 5 Dec 2017 20:20:31 +0000 (14:20 -0600)] 
Add Secureworks rulesets.

From David Wharton.

8 years agomark et/pro as replacing et/open
Jason Ish [Mon, 4 Dec 2017 13:07:19 +0000 (07:07 -0600)] 
mark et/pro as replacing et/open

8 years agoRemove tags until vendors supply them.
Jason Ish [Mon, 4 Dec 2017 13:06:20 +0000 (07:06 -0600)] 
Remove tags until vendors supply them.

8 years agoAdd PT Research Attack Detection ruleset.
Jason Ish [Thu, 30 Nov 2017 18:51:31 +0000 (12:51 -0600)] 
Add PT Research Attack Detection ruleset.

8 years agorename description to summary
Jason Ish [Thu, 30 Nov 2017 17:15:59 +0000 (11:15 -0600)] 
rename description to summary

description is now a multiline description...

8 years agoadd tags; subscribe url
Jason Ish [Wed, 29 Nov 2017 12:32:24 +0000 (06:32 -0600)] 
add tags; subscribe url

8 years agoET URLs have a - before the version.
Jason Ish [Tue, 28 Nov 2017 22:07:52 +0000 (16:07 -0600)] 
ET URLs have a - before the version.

8 years agoalphabetic order; mark et-pro code as a secret
Jason Ish [Tue, 28 Nov 2017 21:37:48 +0000 (15:37 -0600)] 
alphabetic order; mark et-pro code as a secret

8 years agomake the sources a map, keyed by short-name
Jason Ish [Tue, 28 Nov 2017 20:44:13 +0000 (14:44 -0600)] 
make the sources a map, keyed by short-name

8 years agoUse a single index file.
Jason Ish [Tue, 28 Nov 2017 18:11:16 +0000 (12:11 -0600)] 
Use a single index file.

8 years agoDefine parameters
Jason Ish [Mon, 27 Nov 2017 21:59:21 +0000 (15:59 -0600)] 
Define parameters

8 years agoDefine parameters
Jason Ish [Mon, 27 Nov 2017 21:57:07 +0000 (15:57 -0600)] 
Define parameters

8 years agoAdd traffic-id ruleset.
Jason Ish [Mon, 27 Nov 2017 21:15:01 +0000 (15:15 -0600)] 
Add traffic-id ruleset.

8 years agoAdd license and vendor.
Jason Ish [Mon, 27 Nov 2017 21:11:28 +0000 (15:11 -0600)] 
Add license and vendor.

8 years agoAdd SSLBL Suricata SSL FP blacklist rules.
Jason Ish [Mon, 27 Nov 2017 20:13:46 +0000 (14:13 -0600)] 
Add SSLBL Suricata SSL FP blacklist rules.

8 years agoAdd ET Open and Pro
Jason Ish [Mon, 27 Nov 2017 20:09:30 +0000 (14:09 -0600)] 
Add ET Open and Pro