Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66697
This rule looks for HTTP messages indicative of MultiOS.Trojan.Agent outbound command-and-control communications.
1:66696
This rule looks for HTTP messages indicative of Py.Trojan.Agent outbound command-and-control communications.
1:66693
This rule looks for a .NET Message Framing Protocol sized envelope record that includes the "WriteDataFile" operation together with a parent directory traversal pattern in the request payload. Successful exploitation allows an attacker to write arbitrary files to arbitrary locations on the target system, potentially achieving remote code execution.
1:66692
This rule looks for a ".NET Message Framing Protocol" record indicating the "WriteDataFile" operation combined with a target filename ending in ".aspx". Successful exploitation allows an attacker to write arbitrary files to the server, potentially installing a web shell.
1:66691
This rule looks for HTTP requests to the Joomla index.php endpoint with the com_jce option that contain a multipart upload field named profile_file whose filename ends with a prohibited script or executable extension. Successful exploitation may allow an attacker to place executable code on the server and achieve remote code execution.
1:66690
This rule looks for HTTP requests conforming to the pattern of SPECTRE C2 messages.