r39 - 22 Oct 2007 - 11:34:57 - MattJonkmanYou are here: TWiki >  Main Web > WebHome

Bleeding Edge Threats Rule Documentation Wiki

This wiki contains all current rules, added as each is put into the main tarball and cvs repository. The rule author if available is primarily responsible for the documentation of a rule, however the entire community is encouraged and welcomed to contribute or document any rule. You may attach pcaps, packet text, and even code samples to any entry relevant. This is particularly useful for future troubleshooting. Please document if possible where the sample was captured. If you have a sample that's not suitable for posting publicly please contact bleeding@bleedingthreats.net and it can be archived privately, available to any vetted researcher.

AllRulesets

AllProjects

Other Major projects Documented Here: SnortSam BlackHoleDNS

NewSignatureIdeas If you have one, or are looking for an idea to put some time into and learn about.

Last 10 Signature Documentation Changes

Results from Main web retrieved at 05:27 (GMT)

Snort.Conf Samples The goal of this project is to make a set of sample snort.conf files. These will represent different size and goal installs of snort. We do not ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE MALWARE User Agent Containing http\:// Suspicious Likely Spyware/Trojan"; flow:to server ...
JohnMcCash 10 Jan 2008 I have a question for the BleedingThreats audience at large. I was just reading up a bit on Fast Flux DNS configurations, which are being ...
alert udp $HOME NET 1024:65535 $EXTERNAL NET 1024:65535 (msg:"BLEEDING EDGE TROJAN Storm Worm Encrypted Traffic Outbound Likely Search by md5"; dsize:25; threshold ...
My Links .ATasteOfTWiki view a short introductory presentation on TWiki for beginners .WelcomeGuest starting points on TWiki .TWikiUsersGuide ...
My Links .ATasteOfTWiki view a short introductory presentation on TWiki for beginners .WelcomeGuest starting points on TWiki .TWikiUsersGuide ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE TROJAN Downloader.Affill User Agent Detected (lol)"; flow:established,to server; content: ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE TROJAN Win32 ALT C C Initial Infection Checkin"; flow:established,to server; dsize:18; content ...
alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE TROJAN Prg Trojan HTTP POST"; flow:established,to server; content:"POST "; depth:5; uricontent ...
alert udp $HOME NET 1024: $EXTERNAL NET 4099 (msg:"BLEEDING EDGE TROJAN Srizbi registering with controller"; dsize:20; content:" 2d "; offset:6; content:" 2d ...
Number of topics: 10

All additions will be reviewed by the documentation team at Bleeding Edge Threats, a volunteer group. Please report any inaccuracies or wikispam to bleeding@bleedingthreats.net.

To post please register. -- Registration

Follow documentation updates via WebRss or WebAtom

Conventions

All rules are available by accessing the following URL format: http://doc.bleedingthreats.net/SID

i.e. http://docs.bleedingthreats.net/2003434

As a rule is changed the new revision will automatically be placed above the old rule and old comments with an Auto-Added timestamp. This should allow a conversation to be relevant to the revision of the rule at the time. Please post "Yes, that fixed it" comments if a new revision fixes an older issue.

Within each signature entry there is a form to place a comment, suitable for short entries or questions about a rule. For larger posts or formal documentation please use the edit function and place the information below other content. You can use most html tags, recommend using PRE tags with code or packet text to keep it formatted as intended.

Signature authors are informally responsible for initial documentation where necessary. However ANY user may post information they have to contribute, and please do.

Documentation need not be formal. Links to POC code, vulnerability alerts, even mailing list conversations may be added to the rule's documentation. More information is definitely best. The Bleeding Edge Documentation team will review and reformat things as required over time.

See the beginning of a BleedingFAQ

Main Utilities

Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r39 < r38 < r37 < r36 < r35 | More topic actions

 
Docs at Bleeding Threats
This site is powered by the TWiki collaboration platformCopyright © Bleeding Edge Threats.
Ideas, requests, problems regarding TWiki? Send feedback