Back to Rule

Rule History

SID: 10009305 • Source: ptrules/open

Versions (7)

Version DetailsCurrent

Rev: 5Sep 4, 2025, 8:46 AM

TOOLS [PTsecurity] gsocket server activity

alert tcp any any -> any any (msg: "TOOLS [PTsecurity] gsocket server activity"; flow: to_server, established, no_stream; dsize: 128; stream_size: client, <, 500; stream_size: server, <, 100; content: "|01|"; depth: 1; offset: 0; content: !"|00|"; within: 2; content: "|00 00 00 00 00 00 00 00 00 00 00 00|"; fast_pattern; distance: 3; within: 12; content: !"|00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00|"; within: 16; content: !"|00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00|"; distance: 16; within: 16; content: "|00 00 00 00|"; distance: 32; within: 4; content: "|00 00 00 00|"; isdataat: !1, relative; reference: url, gsocket.io; reference: url, rules.ptsecurity.com; classtype: attempted-admin; sid: 10009305; rev: 5;)

Sep 4, 2025, 8:46 AM

Sep 4, 2025, 8:46 AM

Oct 16, 2025, 10:34 AM

Oct 16, 2025, 10:34 AM

rules/ptopen-tools.rules