GPL NETBIOS SMB DCERPC LSASS DsRolerUpgradeDownlevelServer exploit attempt
Query · suricata
flow:to_server,established; flowbits:isset,netbios.lsass.bind.attempt; content:"|FF|SMB"; depth:4; offset:4; nocase; content:"|05|"; distance:59; content:"|00|"; within:1; distance:1; content:"|09 00|"; within:2; distance:19;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
netbios.lsass.bind.attempt- GPL NETBIOS DCERPC LSASS bind attempt
- GPL NETBIOS SMB DCERPC LSASS unicode bind attempt
- GPL NETBIOS SMB DCERPC LSASS bind attempt
- GPL NETBIOS SMB-DS DCERPC LSASS bind attempt
- GPL NETBIOS SMB-DS DCERPC LSASS unicode bind attempt
- GPL NETBIOS DCERPC LSASS direct bind attempt
- GPL NETBIOS SMB DCERPC LSASS direct bind attempt
- GPL NETBIOS SMB-DS DCERPC LSASS direct bind attempt