* Talos combines our security experts from TRAC, SecApps, and VRT teams.
This SRU number: 2017-03-14-002
Previous SRU number: 2017-03-09-002
Applies to:
This SEU number: 1629
Previous SEU: 1627
Applies to:
This is the complete list of rules added in SRU 2017-03-14-002 and SEU 1629.
The format of the file is:
GID - SID - Rule Group - Rule Message - Policy State
The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.
The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.
Note: Unless stated explicitly, the rules are for the series of products listed above.
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 41924 | FILE-OTHER | Notepad++ scilexer.dll dll-load exploit attempt | off | off | off |
1 | 41925 | FILE-OTHER | Notepad++ scilexer.dll dll-load exploit attempt | off | off | off |
1 | 41926 | OS-WINDOWS | Microsoft Win32u NtUserThunkedMenuItemInfo use after free attempt | off | drop | drop |
1 | 41927 | OS-WINDOWS | Microsoft Win32u NtUserThunkedMenuItemInfo use after free attempt | off | drop | drop |
1 | 41928 | OS-WINDOWS | Microsoft Win32k DDI use after free attempt | off | drop | drop |
1 | 41929 | OS-WINDOWS | Microsoft Win32k DDI use after free attempt | off | drop | drop |
1 | 41930 | OS-WINDOWS | Microsoft Win32k DDI use after free attempt | off | drop | drop |
1 | 41931 | OS-WINDOWS | Microsoft Win32k DDI use after free attempt | off | drop | drop |
1 | 41932 | FILE-OTHER | Microsoft Windows Uniscribe privilege escalation attempt | off | drop | drop |
1 | 41933 | FILE-OTHER | Microsoft Windows Uniscribe privilege escalation attempt | off | drop | drop |
1 | 41934 | FILE-OTHER | Microsoft Windows Uniscribe privilege escalation attempt | off | drop | drop |
1 | 41935 | FILE-OTHER | Microsoft Windows Uniscribe privilege escalation attempt | off | drop | drop |
1 | 41936 | BROWSER-IE | Microsoft Edge TypedArray setter arbitrary write attempt | off | drop | drop |
1 | 41937 | BROWSER-IE | Microsoft Edge TypedArray setter arbitrary write attempt | off | drop | drop |
1 | 41938 | BROWSER-IE | Microsoft Edge reverse helper heap buffer overflow attempt | off | drop | drop |
1 | 41939 | BROWSER-IE | Microsoft Edge reverse helper heap buffer overflow attempt | off | drop | drop |
1 | 41940 | OS-WINDOWS | Microsoft Windows TrueTypeFont post table out of bounds write attempt | off | drop | drop |
1 | 41941 | OS-WINDOWS | Microsoft Windows TrueTypeFont post table out of bounds write attempt | off | drop | drop |
1 | 41942 | BROWSER-IE | Microsoft Edge EntrySimpleSlotGetter use after free attempt | off | drop | drop |
1 | 41943 | BROWSER-IE | Microsoft Edge EntrySimpleSlotGetter use after free attempt | off | drop | drop |
1 | 41944 | BROWSER-IE | Microsoft Edge scripting engine security bypass css attempt | off | drop | drop |
1 | 41945 | BROWSER-IE | Microsoft Edge scripting engine security bypass css attempt | off | drop | drop |
1 | 41946 | FILE-IMAGE | Microsoft GDI+ malformed EMF description out of bounds read attempt | off | off | off |
1 | 41947 | FILE-IMAGE | GDI+ malformed EMF description out of bounds read attempt | off | off | off |
1 | 41950 | BROWSER-IE | Microsoft Edge WebAssembly memory corruption attempt | off | drop | drop |
1 | 41951 | BROWSER-IE | Microsoft Edge WebAssembly memory corruption attempt | off | drop | drop |
1 | 41952 | BROWSER-IE | Microsoft Edge local file read information leak attempt | off | drop | drop |
1 | 41953 | BROWSER-IE | Microsoft Edge local file read information leak attempt | off | drop | drop |
1 | 41954 | BROWSER-IE | Microsoft Internet Explorer textarea type confusion attempt | off | drop | drop |
1 | 41955 | BROWSER-IE | Microsoft Internet Explorer textarea type confusion attempt | off | drop | drop |
1 | 41956 | BROWSER-IE | Microsoft Internet Explorer arguments type confusion attempt | off | drop | drop |
1 | 41957 | BROWSER-IE | Microsoft Internet Explorer arguments type confusion attempt | off | drop | drop |
1 | 41958 | BROWSER-IE | Microsoft Edge malformed UTF-8 decode arbitrary read attempt | off | drop | drop |
1 | 41959 | BROWSER-IE | Microsoft Edge malformed UTF-8 decode arbitrary read attempt | off | drop | drop |
1 | 41960 | OS-WINDOWS | Microsoft Windows TrueType Font LookupTable out of bounds write attempt | off | drop | drop |
1 | 41961 | OS-WINDOWS | Microsoft Windows TrueType Font LookupTable out of bounds write attempt | off | drop | drop |
1 | 41962 | FILE-OFFICE | Microsoft Office Word template remote code execution attempt | off | drop | drop |
1 | 41963 | FILE-OFFICE | Microsoft Office Word template remote code execution attempt | off | drop | drop |
1 | 41964 | FILE-OFFICE | Microsoft Word 2010 use-after-free memory corruption vulnerability attempt | off | off | drop |
1 | 41965 | FILE-OFFICE | Microsoft Word 2010 use-after-free memory corruption vulnerability attempt | off | off | drop |
1 | 41966 | OS-WINDOWS | Microsoft Windows TrueTypeFont GSUB table out of bounds write attempt | off | drop | drop |
1 | 41967 | OS-WINDOWS | Microsoft Windows TrueTypeFont GSUB table out of bounds write attempt | off | drop | drop |
1 | 41968 | BROWSER-IE | Microsoft Edge JavascriptProxy SetPropertyTrap type confusion attempt | off | off | off |
1 | 41969 | BROWSER-IE | Microsoft Edge JavascriptProxy SetPropertyTrap type confusion attempt | off | off | off |
1 | 41970 | FILE-IMAGE | GDI+ malformed EMF comment heap access violation attempt | off | drop | drop |
1 | 41971 | FILE-IMAGE | GDI+ malformed EMF comment heap access violation attempt | off | drop | drop |
1 | 41972 | OS-WINDOWS | Microsoft Windows TrueType Font out of bounds write attempt | off | drop | drop |
1 | 41973 | OS-WINDOWS | Microsoft Windows TrueType Font out of bounds write attempt | off | drop | drop |
1 | 41974 | OS-WINDOWS | Microsoft Windows TrueType Font out of bounds write attempt | off | drop | drop |
1 | 41975 | OS-WINDOWS | Microsoft Windows TrueType Font out of bounds write attempt | off | drop | drop |
1 | 41976 | FILE-OFFICE | Microsoft Excel shared strings memory corruption attempt | off | drop | drop |
1 | 41977 | FILE-OFFICE | Microsoft Excel shared strings memory corruption attempt | off | drop | drop |
1 | 41978 | SERVER-SAMBA | Microsoft Windows Samba buffer overflow attempt | off | drop | drop |
1 | 41979 | FILE-OFFICE | Microsoft Excel shared strings memory corruption attempt | off | drop | drop |
1 | 41980 | FILE-OFFICE | Microsoft Excel shared strings memory corruption attempt | off | drop | drop |
1 | 41981 | FILE-OFFICE | Microsoft Office Word out of bounds read attempt | off | off | drop |
1 | 41982 | FILE-OFFICE | Microsoft Office Word out of bounds read attempt | off | off | drop |
1 | 41983 | OS-WINDOWS | Microsoft Windows SMBv1 identical MID and FID type confusion attempt | off | off | drop |
1 | 41984 | OS-WINDOWS | Microsoft Windows SMBv1 identical MID and FID type confusion attempt | off | off | drop |
1 | 41985 | OS-WINDOWS | Microsoft Windows TrueTypeFont post table out of bounds write attempt | off | drop | drop |
1 | 41986 | OS-WINDOWS | Microsoft Windows TrueTypeFont post table out of bounds write attempt | off | drop | drop |
1 | 41987 | BROWSER-IE | Microsoft Edge web address spoofing attempt | off | off | off |
1 | 41988 | BROWSER-IE | Microsoft Edge web address spoofing attempt | off | off | off |
1 | 41989 | FILE-EXECUTABLE | Microsoft Windows Com Session Moniker pivilege escalation attempt | off | off | off |
1 | 41990 | FILE-EXECUTABLE | Microsoft Windows Com Session Moniker pivilege escalation attempt | off | off | off |
1 | 41991 | FILE-OTHER | Microsoft Windows TTF file out of bounds access attempt | off | drop | drop |
1 | 41992 | FILE-OTHER | Microsoft Windows TTF file out of bounds access attempt | off | drop | drop |
1 | 41993 | OS-WINDOWS | Microsoft Windows GDI WMF out of bounds read attempt | off | drop | drop |
1 | 41994 | OS-WINDOWS | Microsoft Windows GDI WMF out of bounds read attempt | off | drop | drop |
1 | 41995 | OS-WINDOWS | Microsoft Windows DDI privilege escalation attempt | off | off | drop |
1 | 41996 | OS-WINDOWS | Microsoft Windows DDI privilege escalation attempt | off | off | drop |
1 | 41997 | OS-WINDOWS | Microsoft GDI+ privilege escalation attempt | off | off | off |
1 | 41998 | OS-WINDOWS | Microsoft GDI+ privilege escalation attempt | off | off | drop |
3 | 41999 | OS-OTHER | TRUFFLEHUNTER TALOS-2017-0296 attack attempt | off | drop | drop |
3 | 42000 | SERVER-OTHER | TRUFFLEHUNTER TALOS-2017-0293 attack attempt | off | off | off |
GID | SID | Rule Group | Rule Message | Policy State | ||
---|---|---|---|---|---|---|
Con. | Bal. | Sec. | ||||
1 | 41948 | BROWSER-IE | Microsoft Edge fetch API same origin policy bypass attempt | off | off | off |
1 | 41949 | BROWSER-IE | Microsoft Edge fetch API same origin policy bypass attempt | off | off | off |
Updated rules can be found at this link.