The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Sample Snort rules file

Prev Next

The following is a sample Snort rules file.

var HTTP_PORTS [80,443,8080]
var HOME_NET [10.0.0.0/8,192.168.0.0/16,172.16.0.0/12,169.254.0.0/16,1.0.0.0/8,2.0.0.0/8]
var EXTERNAL_NET ![$HOME_NET,198.80.42.0/23,198.217.128.0/17,198.241.128.0/17,64.94.118.0/23,66.185.176.0/20]


alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET TROJAN TeleBots BCS-server CnC Beacon_NIDS779"; flow:established,to_server; urilen:1; content:"POST"; http_method; content:"value="; depth:6; http_client_body; fast_pattern; content:!"Content-Type|3a|"; http_header; content:!"Referer|3a|"; http_header; reference:url,www.welivesecurity.com/2016/12/13/rise-telebots-analyzing-disruptive-killdisk-attacks/; classtype:trojan-activity; sid:2023652; rev:1;)

Note

  • The variables and rules can be in separate files. If you are using separate files for variables and rules, ensure that you load the variables before loading the rules.