Поборвка сигнатур IDS SNORT для выявления Agent Tesla, AZORult, Formbook, Ursnif, LokiBot, MOUSEISLAND, NanoCore, Qakbot, Remcos, TrickBot.
Разбор сигнатуры IDS: ET TROJAN Possible WannaCry? DNS Lookup 4
Разбор сигнатуры IDS: AM POLICY RDP session ended with RST
Разбор сигнатуры IDS: ET SCAN Potential SSH Scan OUTBOUND
Разбор сигнатуры IDS: MALWARE-CNC Win.Trojan.Glupteba C&C server HELLO request to client
Разбор сигнатуры IDS: SQL use of sleep function in HTTP header - likely SQL injection attempt
Разбор сигнатуры IDS: ET SCAN Behavioral Unusually fast Terminal Server Traffic Potential Scan or Infection (Inbound)
Разбор сигнатуры IDS: ET TROJAN Possible WannaCry? DNS Lookup 1