Snort Mailing List

Everyone's favorite open source IDS, Snort. This archive combines the snort-announce, snort-devel, snort-users, and snort-sigs lists.

List Archives

Latest Posts

Snort Subscriber Rules Update 2026-04-07 Research via Snort-sigs (Apr 07)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the malware-cnc,
malware-other and server-webapp rule sets to provide coverage for
emerging threats from these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Snort Subscriber Rules Update 2026-04-02 Research via Snort-sigs (Apr 02)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the browser-chrome,
malware-cnc, malware-other and server-webapp rule sets to provide
coverage for emerging threats from these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Snort Subscriber Rules Update 2026-03-31 Research via Snort-sigs (Mar 31)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the file-image,
malware-cnc and server-webapp rule sets to provide coverage for
emerging threats from these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Re: Error in registered TalosLightSPD ruleset released on 2026-03-24? Dheeraj Gupta via Snort-devel (Mar 29)
Following up on this,

The new ruleset released on 2026-03-26 also causes the same error. Although
the reference in load_ips.lua has been removed, there is now a reference to
3.1.25.0 in

policies/common/ruledirs.conf.lua

With the latest ruleset, that line needs to be commented or the sensor will
not start.

Once again I am requesting the signature release admins to let us know if
there is something missing in the registered ruleset (The...

Snort Subscriber Rules Update 2026-03-26 Research via Snort-sigs (Mar 26)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the file-image,
malware-other and server-webapp rule sets to provide coverage for
emerging threats from these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Error in registered TalosLightSPD ruleset released on 2026-03-24? Dheeraj Gupta via Snort-devel (Mar 26)
Hi,

We are using registered ruleset for Snort. After downloading the latest
LightSPD ruleset released on 2026-03-24, our sensor failed to start up with
an error

ERROR: ips.rules:6 can't open ../../rules/3.1.25.0/includes.rules
ERROR: ips.states:6 can't open ../../rules/
3.1.25.0/rulestates-security-ips.states

Looking at the the file lightspd/policies/common/load_ips.lua in the
release, there is a reference to 3.1.25 (which was not...

Error in registered TalosLightSPD ruleset released on 2026-03-24? Dheeraj Gupta via Snort-sigs (Mar 24)
Hi,

We are using registered ruleset for Snort. After downloading the latest
LightSPD ruleset released on 2026-03-24, our sensor failed to start up with
an error

ERROR: ips.rules:6 can't open ../../rules/3.1.25.0/includes.rules
ERROR: ips.states:6 can't open ../../rules/
3.1.25.0/rulestates-security-ips.states

Looking at the the file lightspd/policies/common/load_ips.lua in the
release, there is a reference to 3.1.25 (which was not...

Snort Subscriber Rules Update 2026-03-24 Research via Snort-sigs (Mar 24)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the file-image,
malware-cnc, malware-other and server-webapp rule sets to provide
coverage for emerging threats from these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Snort Subscriber Rules Update 2026-03-05 Research via Snort-sigs (Mar 05)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the and server-webapp
rule sets to provide coverage for emerging threats from these
technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Snort Subscriber Rules Update 2026-03-03 Research via Snort-sigs (Mar 03)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the file-image,
file-other, indicator-shellcode, malware-cnc, malware-other,
server-mail and server-webapp rule sets to provide coverage for
emerging threats from these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Snort Subscriber Rules Update 2026-02-26 Research via Snort-sigs (Feb 26)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the browser-chrome,
file-other, os-windows, policy-other and server-webapp rule sets to
provide coverage for emerging threats from these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Snort Subscriber Rules Update 2026-02-24 Research via Snort-sigs (Feb 24)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the malware-other and
server-webapp rule sets to provide coverage for emerging threats from
these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Snort Subscriber Rules Update 2026-02-19 Research via Snort-sigs (Feb 19)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the file-pdf,
malware-cnc, malware-other and server-webapp rule sets to provide
coverage for emerging threats from these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Snort Subscriber Rules Update 2026-02-17 Research via Snort-sigs (Feb 17)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the malware-other and
server-webapp rule sets to provide coverage for emerging threats from
these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

Snort Subscriber Rules Update 2026-02-12 Research via Snort-sigs (Feb 12)
Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the browser-other,
file-flash, file-pdf, os-windows, policy-other and server-webapp rule
sets to provide coverage for emerging threats from these technologies.

For a complete list of new and modified rules please see:

https://www.snort.org/advisories

More Lists

Dozens of other network security lists are archived at SecLists.Org.