ET EXPLOIT Intel AMT Login Attempt Detected (CVE 2017-5689)
Query · suricata
flow:to_server,established;
http.header;
content:"Authorization|3a 20|Digest";
content:"username=|22|";
content:"response="; fast_pattern;
pcre:"/^\s*\x22{2}/R";
flow:to_server,established;
http.header;
content:"Authorization|3a 20|Digest";
content:"username=|22|";
content:"response="; fast_pattern;
pcre:"/^\s*\x22{2}/R";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.