Re: Snort 3 rules - Antivirus

Jayesh Patel via Snort-sigs <[email protected]>
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <CY5PR12MB6203A3CF4CC8A5F0373064719554A@CY5PR12MB6203.namprd12.prod.outlook.com>
I believe this is normal, since AV detections based on signatures can trigger alert when they see pattern in Snort Rules. I had this alert earlier, it would help to create a folder and exclude that from defender scans. Also, verify the checksum of the file downloaded from Snort, just to be on safe side.

Thanks,
Jayesh

Get Outlook for Android<https://aka.ms/AAb9ysg>
________________________________
From: Snort-sigs <[email protected]> on behalf of Rostanin Gleb SBR DIRCS via Snort-sigs <[email protected]>
Sent: Monday, June 12, 2023 6:30:16 AM
To: [email protected] <[email protected]>
Subject: [Snort-sigs] Snort 3 rules - Antivirus


Dear Snort community,



I recently registered to be able to download the Snort 3 rules. Unfortunately, when downloading, Windows defender started complaining that a Virus was detected. Is this normal behavior or am I currently being attacked 😃?



Kind regards



Gerry

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.