Back to Rule

Rule History

SID: 2049806 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 1Dec 20, 2023, 12:00 PM

ET INFO Simplehelp Remote Administration Suite Default SSL Certificate Observed

alert tls $EXTERNAL_NET any -> $HOME_NET any (msg:"ET INFO Simplehelp Remote Administration Suite Default SSL Certificate Observed"; flow:established,to_client; tls.cert_issuer; content:"C=US, ST=US, L=US, O=Remote Access, OU=Administration, CN=localhost"; fast_pattern; threshold:type limit,seconds 300,count 1,track by_src; reference:url,simple-help.com; classtype:misc-activity; sid:2049806; rev:1; metadata:created_at 2023_12_20, confidence High, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_12_20;)

Dec 20, 2023, 12:00 PM

Dec 20, 2023, 12:00 PM

Sep 21, 2024, 3:00 AM

Aug 15, 2025, 8:34 PM

rules/emerging-info.rules