New RBN Rulesets
By popular demand we’ve pulled the Russian Business Network rules out of the compromised hosts list and into it’s own separate ruleset.
More information here:
http://doc.bleedingthreats.net/bin/view/Main/RussianBusinessNetwork
These have proven quite valuable to many users, I highly recommend tracking any traffic to/from these nets.
Don’t forget to add something like this to your snort.conf if you would like to use them:
include $RULE_PATH/bleeding-rbn.rules
or
include $RULE_PATH/bleeding-rbn-BLOCK.rules
if you’re a Snortsam user.
Matt