Snort 2.8.4 is about to be released “real soon now” This is because of the new dcerpc preprocessor that handles all the decoding functions that were previously taken care of using rules and flowbits in a lot of those rules. The number of netbios rules released for any vulnerability that can be exploited over the preprocessor is going to be reduced greatly. The downside is that this functionality is only available in Snort. There is no backwards compatibility. In order to keep up with current detection, upgrading Snort is the only option.”]
Source: https://blog.talosintelligence.com/2009/02/important-snort-rule-changes-and-new.html

