Re: Rules commented by an #
Patrick Mullen <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.sigs |
|---|---|
| Message-ID | <CAMhPpEVmMYsJHh9FW_CjKx9fiDRkVgpQehGhMqqX6qfsd2MV6A@mail.gmail.com> |
If the rule is preceded by a '#', it is disabled by default. There are various reasons it could be disabled by default -- age, performance, false positives, it's simply "not important enough to be enabled," etc. They are provided to give people the option to enable them if they feel they are applicable to their environment. Thanks, ~Patrick On Mon, Mar 8, 2021 at 9:04 AM hugo.boris--- via Snort-sigs < [email protected]> wrote: > > Hello, > > Can you tell me if the rules commented by an # are optional rules or rules > to be removed ? > > If they happen to be optional, what is the reason or condition that made > it to be commented ? > > Thanks. > > Hugo > _______________________________________________ > Snort-sigs mailing list > [email protected] > https://lists.snort.org/mailman/listinfo/snort-sigs > > Please visit http://blog.snort.org for the latest news about Snort! > > Please follow these rules: > https://snort.org/faq/what-is-the-mailing-list-etiquette > > Visit the Snort.org to subscribe to the official Snort ruleset, make sure > to stay up to date to catch the most <a href=" > https://snort.org/downloads/#rule-downloads">emerging threats</a>! > -- Patrick Mullen Response Research Manager Cisco TALOS _______________________________________________ Snort-sigs mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!