Back to Rule

Rule History

SID: 2016898 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 8May 21, 2013, 12:00 PM

ET HUNTING Suspicious MSIE 10 on Windows NT 5

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET HUNTING Suspicious MSIE 10 on Windows NT 5"; flow:established,to_server; threshold:type limit,track by_src,count 2,seconds 60; http.user_agent; content:" MSIE 10.0|3b| Windows NT 5."; fast_pattern; classtype:bad-unknown; sid:2016898; rev:8; metadata:created_at 2013_05_21, confidence Medium, signature_severity Informational, updated_at 2023_04_18;)

May 21, 2013, 12:00 PM

Apr 18, 2023, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-hunting.rules