In this URL,
https://blog.talosintelligence.com/2018/05/VPNFilter.html?m=...
it mentions snort rules for detection and protection for VPNFilter and ClamAV Signatures.
But it didn't explain how to use them.
The way I understand SNORT after googling it, I need to able captures the traffic (wan port) and feed that to SNORT for analysis, is that correct?
Also for ClamAV, do I need to clone/mount the rootfs from the wifi router to Linux and use ClamAV to scan that rootfs for those signatures?
The URL mentions the infested device have /var/run/vpnfilterm, /var/run/vpnfilterw. I checked they are not in my wifi router's fs.
The URL also mentions it modified/insert entry the crontab, but I can't find what exe name, possible file locations I should search in my router. Do anyone else know such info?