ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM Execution (CVE-2023-24955)
Query · suricata
flow:established,to_server; flowbits:isset,ET.Sharepoint.CVE-2023-24955; http.method; content:"POST"; http.uri; content:"/_vti_bin/client.svc/ProcessQuery"; fast_pattern; endswith; http.request_body; content:"Name|3d 22|ReturnParameterCollection|22|"; content:"|3a|entityfile|3a|"; content:"|3a|lsifile|3a|"; target:dest_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.Sharepoint.CVE-2023-24955