How Suricata Can Help Identify Zero-Day Exploits in Your Network

Ready to start learning? Individual Plans →Team Plans →

Zero-day exploits are hard to catch because they usually do not match anything in your signature database. That is exactly where zero-day detection becomes a network visibility problem, not just a malware problem. Suricata can help by inspecting packets, tracking flows, parsing protocols, and surfacing behavior that looks wrong even when the exploit itself is still unknown.

Featured Product

CompTIA Cybersecurity Analyst CySA+ (CS0-004)

Learn to analyze security threats, interpret alerts, and respond effectively to protect systems and data with practical skills in cybersecurity analysis.

Get this course on Udemy at the lowest price →

Quick Answer

Suricata helps with zero-day detection by spotting abnormal network behavior, malformed protocol use, suspicious flows, and exploit-like traffic patterns before a file-based tool may recognize the threat. Deployed at key choke points and tuned with good baselines, Suricata adds actionable evidence to incident response and supports faster triage when no known signature exists.

Quick Procedure

  1. Place Suricata at the most important network choke points.
  2. Baseline normal protocols, destinations, and flow rates.
  3. Enable relevant signatures, protocol parsers, and metadata logging.
  4. Tune noisy rules and set thresholds for your environment.
  5. Correlate alerts with SIEM, EDR, and threat intelligence.
  6. Triage suspicious traffic using asset criticality and vulnerability data.
  7. Preserve packets, scope the incident, and contain confirmed activity.
Primary UseNetwork-based zero-day detection through protocol-aware inspection and flow analysis
Best Detection InputsAlerts, flows, packet captures, protocol anomalies, and metadata
Best PlacementInternet edge, east-west internal segments, VPN, and critical application paths
Core StrengthFinding suspicious behavior when no exact exploit signature exists
Main LimitationCannot inspect traffic it cannot see, especially encrypted traffic without supporting controls
Operational FitWorks best with SIEM, EDR, threat intelligence, and vulnerability management
Reference ModelsNIST Cybersecurity Framework and CISA guidance on detection and response

Introduction

Traditional Signature-Based Detection works well when the threat is already known. It fails when the attacker is using a fresh exploit, a newly disclosed vulnerability, or a technique that has not been written into a rule yet. That is why zero-day attacks often slip through perimeter defenses and show up later as strange connections, odd protocols, or post-exploitation callbacks.

Suricata is a network security engine that provides packet inspection, protocol analysis, flow tracking, and alert generation. It is especially useful when you need visibility into exploit behavior instead of just file hashes or antivirus matches. The official project documentation at Suricata explains its IDS, IPS, and network security monitoring capabilities, while CISA continues to emphasize layered detection and incident response for fast-moving threats.

This guide shows how zero-day detection works in practice with Suricata. You will see how zero-day traffic behaves, where Suricata is strongest, how to tune it, and how to use its alerts during incident response. It also connects the network view to the rest of the stack, including SIEM, EDR, threat intelligence, and vulnerability data. That matters because Suricata is most valuable when it becomes part of a broader investigation workflow, not a standalone alert generator.

Zero-day attacks are often visible before they are identifiable. The network usually shows the first clues: malformed requests, strange session timing, and unusual destinations that do not fit the baseline.

How Zero-Day Exploits Behave on the Network

A zero-day exploit is an attack that takes advantage of a vulnerability that defenders have not yet patched or fully recognized. In practical terms, the exploit matters more than the malware payload. The first network signs are often weak signals: an HTTP request with the wrong structure, a DNS lookup for a newly registered domain, or a TLS session that behaves differently from normal application traffic.

The CISA Known Exploited Vulnerabilities Catalog is useful for tracking widely exploited issues, but zero-day attacks often appear before public tracking catches up. That means defenders need to look for behavior, not just indicators. The OWASP project also reinforces a practical point: exploitation techniques often abuse protocol logic, input handling, and trust boundaries rather than relying on obviously malicious files.

What the network usually shows first

Early-stage compromise can look boring if you only scan for malware signatures. A compromised host may begin by contacting a rare destination, retrying a connection in short bursts, or sending malformed headers that trigger parser errors. Attackers also use obfuscation, protocol abuse, and trusted services to blend into ordinary traffic.

  • Unusual destination lookups such as rare DNS requests or newly seen hosts.
  • Malformed requests that do not fully match the protocol specification.
  • Abnormal session timing including repeated short connections or beacon-like intervals.
  • Post-exploitation traffic such as enumeration, scanning, or callback channels.
  • Lateral movement signals when a host begins talking to internal systems it normally ignores.

Suricata becomes useful because it can separate the first exploit traffic from the later stages of compromise. That helps analysts answer the questions that matter: what talked first, what happened next, and which hosts may already be involved. In a practical Incident Response workflow, those answers are what turn a suspicious packet into a scoped event.

Why Suricata Is Effective for Zero-Day Detection

Suricata is effective because it inspects traffic at multiple levels. It does not just look at payload bytes. It tracks packets, flows, and application protocols so it can recognize when something is out of place. That makes it valuable for anomaly detection, especially when the attacker uses an unknown payload but still has to speak a recognizable protocol.

The official Suricata documentation at docs.suricata.io describes protocol decoding, detection engine behavior, and metadata generation. That matters because protocol awareness lets Suricata notice things like invalid headers, incorrect sequencing, unexpected methods, or suspicious use of a protocol field. A malicious HTTP request does not need a known malware hash if it already breaks the rules of the protocol.

Why context matters more than a perfect signature

When no exact signature exists, context becomes the detection signal. Suricata can still raise suspicion when a flow looks wrong relative to the environment. For example, a workstation that normally browses public SaaS applications but suddenly starts sending malformed SMB traffic to an internal server deserves attention even if no CVE-specific rule fires.

  • Packet inspection surfaces suspicious content and protocol violations.
  • Flow analysis reveals frequency, direction, and duration patterns.
  • Protocol parsing helps identify abuse of HTTP, DNS, SMB, TLS, and other common services.
  • Metadata supports forensic review even when the payload itself is encrypted.
  • Packet capture gives analysts evidence they can revisit during scoping and containment.

Suricata fits best at the front end of investigation. It is the system that says, “this traffic deserves a closer look.” The analyst still has to validate the event, check host telemetry, and determine whether the traffic is exploit traffic, post-exploitation activity, or benign weirdness.

Known signature match Good for confirmed threats and threat intel hits
Protocol anomaly Good for malformed or noncompliant traffic that may indicate abuse

MITRE ATT&CK is also useful here because many attacker techniques are easier to recognize as patterns of behavior than as isolated exploit strings. Suricata helps you see those patterns on the wire.

What Detection Methods Matter Most in Suricata?

Detection method choice matters because zero-day defense gets stronger when multiple views overlap. Suricata is not just a signature engine. It can combine known-rule matches, protocol anomalies, flow behavior, and payload inspection to create a more reliable picture of suspicious activity. That layered approach is exactly what you want when the exploit is unknown.

The FIRST Exploit Prediction Scoring System shows how defenders increasingly prioritize risk based on exploit likelihood, but an unknown exploit will not always have a score. Suricata closes that gap by looking for the behavior that exploit attempts must still produce. A malicious payload still has to cross the network, speak some protocol, and interact with a target.

How the major methods compare

Signature rules catch what is already understood. Protocol anomaly detection catches deviations from normal formatting or sequence. Flow analysis catches timing, volume, and directionality that do not fit the baseline. File and payload inspection can help when malicious content is embedded inside a transfer or downloaded as part of a delivery chain.

  • Signature-based detection is best for known exploits, IOC matches, and threat intel feeds.
  • Protocol anomaly detection is best for malformed requests, invalid headers, and odd state transitions.
  • Flow-based analysis is best for beaconing, bursts, retries, and suspicious persistence of connections.
  • Payload and file inspection is best when content is embedded in HTTP, SMB, or other application traffic.

The practical lesson is simple: do not rely on one rule type. If your detection stack only cares about exact strings, you will miss many early-stage exploit attempts. If you only look at anomalies, you may drown in noise. Suricata is strongest when it applies all of its methods together and then hands the result to an analyst or SIEM for context.

Note

Zero-day detection is probabilistic, not guaranteed. The goal is to raise the quality of suspicion early enough that an analyst can validate and contain the event before it becomes a breach.

Where to Place Suricata for Maximum Visibility

Placement determines what Suricata can actually see. A sensor on the wrong segment may generate good alerts on low-value traffic while missing the path attackers use to reach important systems. For zero-day detection, the best placement is usually where critical traffic converges or exits the environment.

For edge visibility, place Suricata at north-south choke points such as internet gateways, perimeter firewalls, VPN ingress, and proxy exits. For internal visibility, place it on east-west segments that carry traffic between user networks, servers, and sensitive application tiers. The NIST Cybersecurity Framework supports this kind of layered monitoring because it improves detection coverage and response speed.

High-value locations to monitor

  • Domain controllers and identity services where compromise can spread quickly.
  • VPN gateways and remote access paths that often see attacker pivoting.
  • Application tiers that handle public-facing traffic and backend communication.
  • Cloud mirror points where virtual traffic can be inspected consistently.
  • Internal segmentation points where lateral movement becomes visible.

Hybrid environments complicate this. Traffic may live in cloud virtual networks, across container overlays, or behind managed load balancers. In those cases, you need mirrored traffic, virtual sensors, or cloud-native log integration so Suricata is not blind to a key path. The big risk is assuming a sensor exists “somewhere” when the actual exploit path bypasses the monitored route.

If you cannot see the traffic, you cannot detect the exploit. Sensor placement is not a deployment detail. It is a detection decision.

Prerequisites

Before you try to use Suricata for zero-day hunting, make sure the operational basics are already in place. A well-placed sensor without baseline data or logging integration will produce alerts, but not useful investigations. That is a common failure point in security monitoring projects.

  • Network visibility through span ports, TAPs, mirror traffic, or virtual sensor paths.
  • Administrative access to deploy, tune, and update Suricata rules and config.
  • Packet capture storage or enough metadata retention to support review.
  • SIEM integration for correlation with firewall, DNS, identity, and endpoint logs.
  • EDR access for host-side confirmation of suspicious activity.
  • Known baseline data such as normal ports, destinations, and connection rates.
  • Vulnerability data to determine which assets are actually exposed.

If your team is still building skills around alert analysis and correlation, the CompTIA Cybersecurity Analyst (CySA+) course content from ITU Online IT Training is relevant here because it maps well to interpreting alerts, triaging threats, and understanding how network evidence supports incident response.

How to Build a Strong Baseline Before You Hunt

A strong baseline is the difference between useful anomaly detection and a wall of noise. Baselining is the process of documenting what normal traffic looks like so deviations stand out. Without it, every odd connection looks suspicious, and analysts quickly stop trusting the alerts.

Start with the traffic that matters most. Track common protocols, usual ports, frequent destinations, average session counts, and typical business-hour patterns. The SANS Institute has long emphasized that meaningful detection depends on knowing the normal environment first, and that advice still holds. The baseline should also be segmented. A finance server, an engineering workstation, and a domain controller do not share the same normal profile.

What to baseline first

  1. Protocols that each segment actually uses.
  2. Ports and services that are common for each asset class.
  3. Destination patterns such as SaaS platforms, update servers, and partner networks.
  4. Connection timing including bursts, retries, and off-hours activity.
  5. Alert history to see which patterns are benign and which repeat during incidents.

Use flow logs and historical alerts to establish what “normal” means in your Environment. Refresh that baseline after major changes such as a cloud migration, a new remote access platform, or an application rollout. A baseline that is six months old in a changing network is not a baseline. It is stale documentation.

Which Alert Patterns May Point to Zero-Day Activity?

The most valuable Suricata alerts for zero-day hunting are often the ones that look incomplete or slightly wrong. A single alert may not prove exploitation, but it can be the first breadcrumb in a chain of evidence. The trick is knowing which patterns deserve escalation.

Signature-Based Detection will still catch known attacker infrastructure and public exploit patterns, but zero-day activity often shows up as malformed protocol exchanges, unusual retries, or suspicious callback behavior. The Verizon Data Breach Investigations Report consistently shows that attackers use a mix of initial access, credential abuse, and lateral movement. That is why the network pattern matters even when the original exploit is not obvious.

Patterns worth escalating

  • Malformed or incomplete protocol exchanges that indicate parser abuse or exploit testing.
  • Rare destinations that a host has never contacted before.
  • New or suspicious domains tied to callbacks, redirect chains, or staging infrastructure.
  • Beacon-like timing with periodic or repeated short-lived connections.
  • Internal enumeration that follows the first suspicious external contact.

One noisy alert is not enough. Two or three correlated signals are far more useful. A workstation that makes a strange outbound connection, then starts probing internal hosts, then triggers a protocol anomaly on a file share is worth immediate review. That is how zero-day detection moves from theory to operational value.

How Do You Tune Suricata Without Missing Real Threats?

Suricata tuning is about removing noise without deleting the evidence you will need later. If you leave every rule enabled, analysts drown in alerts. If you disable too much, the sensor becomes blind. The right balance depends on your traffic, not on a generic rule pack.

Start by prioritizing high-confidence signatures and reputable feeds, then add suppressions for clearly understood business traffic. The official guidance from Netresec and the Suricata community often stresses practical rule management and sensor validation. Rule tuning should also be environment-specific. A noisy DNS rule in a research network may be useful in a finance subnet, but a nuisance in a lab.

Tuning decisions that usually work

  1. Disable rules that are noisy and low-value in your environment.
  2. Threshold repeated alerts so one chatty host does not flood the queue.
  3. Suppress known-benign internal services that trigger expected patterns.
  4. Prioritize high-risk assets such as identity systems and public-facing servers.
  5. Retest after every major rule or config change.

Do not tune once and walk away. Traffic changes, attackers change, and new applications create new baseline behavior. If you are using Suricata to support zero-day defense, every tuning decision should be documented so the team knows why a rule was kept, suppressed, or thresholded.

How Does Suricata Metadata Speed Up Investigation?

Metadata is the difference between “an alert happened” and “here is what happened, who did it, and where to look next.” Suricata can add useful context such as source and destination IPs, ports, protocol details, timestamps, and flow direction. That context is what lets analysts pivot from a single event to a broader incident picture.

Forensic review becomes much faster when packet evidence and alert records are retained together. If an exploit is suspected, analysts can examine the request that triggered the alert, determine whether the target responded, and map whether the session led to follow-on activity. This is especially important when payloads are encrypted or partially missing from logs. In those cases, metadata may be the only reliable evidence of what happened.

When Suricata is paired with packet capture, analysts can answer practical questions quickly: Did the exploit attempt succeed? Was there a second-stage download? Did the host start scanning internal systems afterward? Those are the questions that determine whether the event stays a low-level alert or becomes an incident response case.

Alert data Tells you that something matched a rule or anomaly
Flow data Tells you how the connection behaved over time

How Do You Correlate Suricata With SIEM, EDR, and Threat Intelligence?

Suricata is most valuable when its alerts are enriched by other data sources. A suspicious network event by itself may be interesting, but the same event plus endpoint telemetry, identity logs, and asset context becomes actionable. That is the real value of correlation.

For example, if Suricata detects a suspicious outbound connection and your Microsoft Sentinel or other SIEM platform shows a failed login burst followed by privileged authentication, the situation changes quickly. If EDR also shows a new process, persistence attempt, or script execution, the network event is no longer isolated. It becomes a likely compromise chain.

What each source contributes

  • SIEM connects network events to identity, firewall, DNS, and server logs.
  • EDR confirms whether suspicious network behavior matches host execution.
  • Threat intelligence identifies known attacker infrastructure and risky domains.
  • Vulnerability management tells you whether the affected asset was exposed.

ISC2 and ISACA both support the larger governance idea behind this approach: security operations work better when controls, data, and response are aligned. In practice, correlation is what turns Suricata from a packet sensor into a decision-support tool for defenders.

What Should Incident Response Look Like for Suspected Zero-Day Exploits?

Incident response should begin with triage, not panic. A suspicious Suricata alert is not automatically a breach, but it is also not something to ignore. The right process is to validate the alert, assess the asset, and look for related activity before deciding whether containment is needed.

The NIST incident handling guidance remains a solid operational reference for this kind of workflow. Start with exposure. If the alert involves a critical system, a public-facing service, or a host with a known vulnerability, escalation should happen faster. Then scope the event by finding related destinations, subsequent flows, and any internal movement after the first contact.

A practical triage flow

  1. Validate the alert against the baseline and traffic history.
  2. Check exposure by matching the target to current vulnerability data.
  3. Scope all related sessions, domains, and internal connections.
  4. Contain confirmed activity by isolating hosts or blocking destinations.
  5. Preserve evidence including packets, logs, and timestamps for later review.

Preservation matters because zero-day cases often become more important after the fact. The first alert may look small, but later investigation may reveal a compromise path that includes remote access abuse, credential theft, or internal enumeration. Good evidence handling keeps that investigation possible.

Warning

Do not rely on a single Suricata alert to declare compromise. Correlate with host activity, identity events, and asset exposure before you lock down production systems.

Encrypted traffic has changed the job. A growing share of application traffic now hides inside TLS, which means defenders often see less payload detail and more metadata. That pushes zero-day detection toward flow behavior, endpoint validation, and selective decryption or proxy inspection where policy allows it. The Cloudflare Learning Center and vendor guidance across the industry repeatedly highlight how encryption improves privacy while reducing direct packet inspection visibility.

Hybrid and cloud-first architectures add another challenge. Traffic may move between on-prem systems, cloud services, managed identities, and third-party platforms. Attackers know this and increasingly use trusted infrastructure, short-lived domains, and cloud-hosted services to blend in. That makes behavioral anomalies and sequence analysis more important than ever.

Why the detection model keeps changing

  • Encryption reduces payload visibility and increases the value of metadata.
  • Cloud services provide attacker cover because they look normal on the wire.
  • Short-lived infrastructure makes static blocking less effective.
  • Post-exploitation behavior is often easier to detect than the original exploit.

That is why modern teams use network, endpoint, and identity data together. A single control rarely tells the whole story anymore. Suricata still matters because it gives defenders a network lens on the earliest part of the attack chain, which is often the best chance to intervene before damage spreads.

What Limitations Do You Need to Plan Around?

Suricata is powerful, but it is not magic. If the traffic does not pass a monitored path, Suricata cannot see it. If the payload is encrypted and you do not have a decryption strategy or supporting logs, the sensor may only see metadata. And if the rules are badly tuned, the alert queue will become so noisy that real threats get lost.

Another limitation is attacker adaptation. Once defenders deploy stronger network monitoring, attackers often shift to allowed services, covert channels, or trusted platforms. That means a good deployment still needs endpoint coverage, identity monitoring, and response procedures. The CISA StopRansomware guidance reflects the same principle: resilience depends on layered controls, not one tool.

Zero-day detection is therefore a probability game. You are looking for the strongest available evidence, not absolute proof. Suricata improves your odds by catching abnormal traffic early, but the final decision still depends on analyst judgment and correlation.

Best Practices for a More Mature Suricata Deployment

A mature deployment is maintained, not installed once. The rule set should stay current, the sensors should stay in the right places, and the baseline should evolve with the business. That is the difference between a functioning detection program and a stale monitoring stack.

Use the vendor and community ecosystem to stay current. The official Suricata site and documentation at suricata.io are the first place to check for supported features and updates. Pair that with regular validation exercises so you know whether a tuning change removed critical visibility or simply cleaned up noise.

Operational habits that pay off

  1. Update rules and feeds on a regular schedule.
  2. Review sensor placement after every major network change.
  3. Refresh baselines after migrations, mergers, or application rollouts.
  4. Test detections using controlled traffic and incident response drills.
  5. Document decisions so analysts handle alerts consistently.

That discipline is especially important for teams supporting compliance-driven environments. If you need evidence of detection and response maturity, documented tuning decisions and validated sensor placement matter as much as the alert itself. For many organizations, that is the difference between being able to investigate an event and being able to prove how the environment was protected.

Key Takeaway

  • Zero-day detection works best when you look for suspicious behavior, not just known signatures.
  • Suricata helps by inspecting packets, parsing protocols, tracking flows, and retaining forensic metadata.
  • Sensor placement determines what you can see, especially across edge, east-west, cloud, and VPN traffic.
  • Baselines and tuning are essential if you want actionable alerts instead of noise.
  • Correlation with SIEM, EDR, and threat intelligence turns isolated alerts into a real investigation.
Featured Product

CompTIA Cybersecurity Analyst CySA+ (CS0-004)

Learn to analyze security threats, interpret alerts, and respond effectively to protect systems and data with practical skills in cybersecurity analysis.

Get this course on Udemy at the lowest price →

Conclusion

Zero-day exploits are rarely caught because of a perfect signature on day one. They are caught because defenders notice traffic that does not fit the baseline, use that signal to scope the event, and respond before the attack spreads. That is where Suricata earns its place in the stack.

By combining protocol inspection, flow analysis, metadata, and alerting, Suricata gives defenders a practical way to improve zero-day detection. It works best when you deploy it at the right choke points, tune it to your environment, and correlate it with SIEM, EDR, threat intelligence, and vulnerability data. That is how network visibility turns into faster investigation and better containment.

If you are building these skills for operational security work, the Suricata workflow aligns closely with the kind of alert analysis and incident triage covered in ITU Online IT Training’s CompTIA Cybersecurity Analyst (CySA+) course. The next step is straightforward: review your current sensor placement, verify your baselines, and test whether Suricata can see the traffic path that matters most in your environment.

Suricata® is a registered trademark of the Open Information Security Foundation.

[ FAQ ]

Frequently Asked Questions.

How does Suricata detect zero-day exploits if they aren’t in signature databases?

Suricata detects zero-day exploits by analyzing network traffic for abnormal patterns and behaviors rather than relying solely on signature matching. It employs advanced traffic inspection techniques to identify anomalies that could indicate malicious activity.

This approach allows Suricata to recognize suspicious behaviors, such as unusual protocol usage, unexpected flow patterns, or anomalies in packet payloads, which are typical indicators of zero-day exploits. By focusing on behavior rather than signatures, it can surface potential threats even if they are previously unknown.

What features of Suricata make it effective in zero-day exploit detection?

Suricata’s effectiveness in zero-day detection stems from its multi-layered inspection capabilities, including deep packet inspection, protocol parsing, and flow tracking. These features enable it to analyze traffic in detail and identify deviations from normal network behavior.

Additionally, Suricata’s ability to perform real-time analysis and integrate with behavioral anomaly detection systems enhances its capacity to surface unknown threats. Its flexible rule engine also allows security teams to customize detection criteria for emerging threats.

Can Suricata be integrated with other tools for better zero-day detection?

Yes, Suricata can be integrated with various security tools such as Security Information and Event Management (SIEM) systems, intrusion detection systems (IDS), and threat intelligence platforms. This integration enhances its ability to correlate data and improve detection accuracy for zero-day exploits.

By sharing insights and alerts across different systems, organizations can achieve a more comprehensive security posture. Combining Suricata’s behavioral analysis with threat intelligence feeds helps in early identification of emerging threats and zero-day vulnerabilities.

What are common misconceptions about zero-day detection with Suricata?

A common misconception is that Suricata alone can detect all zero-day exploits. While Suricata is powerful, it works best as part of a layered security strategy that includes threat intelligence, endpoint protection, and user awareness.

Another misconception is that zero-day exploits are always highly sophisticated and impossible to detect. In reality, many zero-day attacks exhibit behaviors or anomalies that Suricata can identify through behavioral analysis, even if the specifics are unknown. Understanding these nuances is key to effective detection.

How should organizations optimize Suricata for zero-day exploit detection?

Organizations should configure Suricata to perform comprehensive traffic analysis, including protocol parsing, flow tracking, and anomaly detection. Regularly updating detection rules and integrating threat intelligence feeds can improve sensitivity to emerging threats.

It’s also critical to analyze network logs and alerts continuously, adjusting detection parameters based on observed traffic patterns. Combining Suricata with other security measures, such as endpoint detection and response (EDR) tools, further strengthens the ability to identify and respond to zero-day exploits effectively.

Related Articles

Ready to start learning? Individual Plans →Team Plans →
Discover More, Learn More
Ethical Network Configuration Auditing: How To Identify And Remediate Insecure Settings Discover how to identify and remediate insecure network settings through ethical configuration… How to Use Penetration Testing to Identify Network Vulnerabilities Discover how penetration testing reveals network vulnerabilities and enhances your cybersecurity strategies… How to Harden Windows Server 2022 Against Zero-Day Exploits Learn effective strategies to harden Windows Server 2022 against zero-day exploits and… Zeek And Suricata Integration: Creating A Comprehensive Network Defense System Discover how to integrate Zeek and Suricata to enhance your network security… How To Protect Mobile Platforms From Zero-Day Exploits Discover effective strategies to protect mobile platforms from zero-day exploits by implementing… Using Suricata to Detect and Respond to Internal Network Threats Learn how to leverage Suricata for detecting and responding to internal network…
FREE COURSE OFFERS