Back to Rule

Rule History

SID: 2034094 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 2Oct 4, 2021, 12:00 PM

ET INFO HTTP/2 Traffic (SET)

alert tcp any any -> any any (msg:"ET INFO HTTP/2 Traffic (SET)"; flow:established,to_server; stream_size:server,<,5; content:"|50 52 49 20 2a 20 48 54 54 50 2f 32 2e 30 0d 0a 0d 0a 53 4d 0d 0a 0d 0a|"; startswith; flowbits:set,ET.http2; flowbits:noalert; classtype:misc-activity; sid:2034094; rev:2; metadata:created_at 2021_10_04, confidence High, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_10_04;)

Oct 4, 2021, 12:00 PM

Oct 4, 2021, 12:00 PM

Sep 21, 2024, 3:00 AM

Sep 8, 2025, 9:34 PM

rules/emerging-info.rules