ET MALWARE MACE C2 Framework Response M1
Query · suricata
flow:established,to_client; flowbits:isset,ET.maceframework; http.stat_code; content:"200"; http.server; content:"BaseHTTP"; fast_pattern; startswith; content:"Python/"; distance:0; http.header; content:!"Content-Length"; file.data; content:"null"; bsize:4; target:dest_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.maceframework