ET EXPLOIT Successful Apache ActiveMQ Remote Code Execution (CVE-2023-46604)
Query · suricata
flow:established,to_client; xbits:isset,ET.CVE-2023-46604.attempt, track ip_dst; http.response_body; content:"|3c|bean"; content:"|22|java|2e|lang|2e|ProcessBuilder|22|"; nocase; fast_pattern; distance:0; content:"init|2d|method|3d 22|start|22|"; within:100; content:"constructor|2d|arg"; distance:0; target:dest_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata xbits
ET.CVE-2023-46604.attempt