Removed rule. This rule is known, but it is no longer present in its source. Showing the last known version.Removed: Jul 5, 2026, 4:07 AM

THL OpenStrike Gen4 Beacon Output Submission POST /submit?id=[hex8]

SID: 1900036Rev: 1Enabled3 viewsHistory
Filehunters-ledger.rules
CreatedApril 8, 2026
UpdatedApril 8, 2026
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"THL OpenStrike Gen4 Beacon Output Submission POST /submit?id=[hex8]"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/submit?id="; pcre:"/\/submit\?id=[0-9a-f]{8}$/U"; threshold:type limit,track by_src,count 1,seconds 60; sid:1900036; rev:1; metadata:affected_product Windows, attack_target Client_Endpoint, created_at 2026_04_08, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2026_04_08;)

Metadata

affected productWindows
attack targetClient_Endpoint
created at2026_04_08
deploymentPerimeter
performance impactLow
signature severityMajor
updated at2026_04_08

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!