ET EXPLOIT GTPDoor Trigger Packet Response
Query · suricata
flow:stateless,to_client; content:"|02|"; offset:1; depth:1; content:"|72 1f 18 08|"; distance:15; within:4; fast_pattern; xbits:isset,ET.gptdoor.udp,track ip_pair,expire 10; threshold:type limit,track by_dst,count 1,seconds 600; target:src_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata xbits
ET.gptdoor.udpwithin 10s