Sagan critical stable other

[FORTINET] Malicious Code Detected - Direction Outgoing

[FORTINET] Malicious Code Detected - Direction Outgoing

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[FORTINET] Malicious Code Detected - Direction Outgoing"; content:"subject=Intrusion "; content:"trigger=Default-Malicious-Code-Detection-By-"; content:!"severity=
| 22
| info
| 22
| "; pcre:"/srcip=(?:(10\.
| 172\.(1[6-9]
| 2[0-9]
| 3[0-1])\.
| 192\.168\.))\d{1,3}\.\d{1,3}\.\d{1,3}/"; pcre:"/dstip=(?!(10\.
| 172\.(1[6-9]
| 2[0-9]
| 3[0-1])\.
| 192\.168\.))\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}/"; reference:url,https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/ef4bde1e-412e-11ee-8e6d-fa163e15d75b/FortiAnalyzer-7.4.1-Administration_Guide.pdf; parse_src_ip:2; parse_dst_ip:3; content:!"- - - -"; classtype:trojan-activity; sid:5014365; rev:4;)

Field Validations

Loading…

Comments (0)

Loading comments...