Versions (2)
Version DetailsCurrent
Rev: 1 • Sep 29, 2025, 12:00 PMET HUNTING Observed Zip Slip in TAR Archive (../) Upload M1
alert tcp any any -> $HOME_NET any (msg:"ET HUNTING Observed Zip Slip in TAR Archive (../) Upload M1"; flow:established,to_server; file.magic; content:"POSIX tar archive"; file.data; content:"|00 00 00 2e 2e 2f|"; fast_pattern; reference:url,security.snyk.io/research/zip-slip-vulnerability; classtype:misc-attack; sid:2064948; rev:1; metadata:attack_target Server, created_at 2025_09_29, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Minor, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_09_29, mitre_tactic_id TA0005, mitre_tactic_name Defense_Evasion, mitre_technique_id T1027, mitre_technique_name Obfuscated_Files_or_Information; target:dest_ip;)
Sep 29, 2025, 12:00 PM
Sep 29, 2025, 12:00 PM
Sep 29, 2025, 9:34 PM
Sep 30, 2025, 9:36 PM
rules/emerging-hunting.rules