ET ATTACK_RESPONSE Possible CVE-2016-1287 Inbound Reverse CLI Shellcode
Query · suricata
flow:to_server;
content:"|ff ff ff|tcp/CONNECT/3/";
pcre:"/^(?:\d{1,3}\.){3}\d{1,3}\/\d+\x00$/Ri";
flow:to_server;
content:"|ff ff ff|tcp/CONNECT/3/";
pcre:"/^(?:\d{1,3}\.){3}\d{1,3}\/\d+\x00$/Ri";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.