OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Talos_LightSPD.tar.gz and snortrules-snapshot-31470.tar.gz
« previous next »
  • Print
Pages: [1]

Author Topic: Talos_LightSPD.tar.gz and snortrules-snapshot-31470.tar.gz  (Read 790 times)

dotgate

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Talos_LightSPD.tar.gz and snortrules-snapshot-31470.tar.gz
« on: June 26, 2024, 09:35:51 pm »
Talos_LightSPD.tar.gz and snortrules-snapshot-31470.tar.gz and snortrules-snapshot-29151.tar.gz

When I download above files on windows machine they show as virus files.

Kindly help.

(source of files: https://www.snort.org/downloads)

Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6925
  • Karma: 584
    • View Profile
Re: Talos_LightSPD.tar.gz and snortrules-snapshot-31470.tar.gz
« Reply #1 on: June 26, 2024, 10:01:04 pm »
So your Windows AV product flags these files? How is this OPNsense related?
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

someone

  • Full Member
  • ***
  • Posts: 115
  • Karma: 2
    • View Profile
Re: Talos_LightSPD.tar.gz and snortrules-snapshot-31470.tar.gz
« Reply #2 on: June 26, 2024, 10:05:19 pm »
When I ran antivirus on snort rules or suricata rules It would trigger virus alert
If those files havnt been tampered with they may be good, and from a good source
Some of the same parts that make a rule also triggers antivirus alert
Its not the virus itself, just parts they can grab to identify it, words, actions, etc
Snort rules will not run in suricata and vice versa, two different engines
Only a few out of 150,000 rules, not worth the effort of converting them
Unless you are trying to develop a specific rule on a specific packet flow
They take packets of the virus intrusion or whatever it is
And feed it into one of the engines to make a rule
Some of these rules that are output are not in human readable form
Logged

dotgate

  • Newbie
  • *
  • Posts: 3
  • Karma: 0
    • View Profile
Re: Talos_LightSPD.tar.gz and snortrules-snapshot-31470.tar.gz
« Reply #3 on: June 26, 2024, 10:12:44 pm »
Quote from: Patrick M. Hausen on June 26, 2024, 10:01:04 pm
So your Windows AV product flags these files? How is this OPNsense related?
Given that such files drive how ids and ips services in opnsense will respond to threats,

And they are updated frequently, one must make sure  protector is not the devil
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Intrusion Detection and Prevention »
  • Talos_LightSPD.tar.gz and snortrules-snapshot-31470.tar.gz
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2