hi.
https://rules.emergingthreats.net/open/suricata-5.0/rules/
https://rules.emergingthreats.net/open/suricata-4.0/rules/
#suricata -V
This is Suricata version 5.0.5 RELEASE
I see ET open/emerging-trojan, this rules is removed at suricata 5.0
confuse :-\ ??
Hi,
We're still using the suricata 4 ruleset for ET Pro telemetry (and et-open), at Proofpoint their busy migrating the Telemetry feed to the newer version. The rules in both (4 and 5) are roughly the same, but organised a bit differently and a likely a bit more performant.
The migration code was already available (https://github.com/opnsense/core/commit/41eefdd105012137d9d7db71e70847f9ea8e974), but is waiting for Proofpoint in this case.
Best regards,
Ad