ET HUNTING Suspicious HTTP Connection Header Observed
Sourceet/open
CreatedMay 6, 2022
UpdatedMay 9, 2022
Classificationmisc-activity
alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Suspicious HTTP Connection Header Observed"; flow:established,to_server; http.connection; content:!"upgrade"; nocase; content:!"keep-alive"; nocase; content:!"close"; nocase; http.header_names; content:"|0d 0a|Connection|0d 0a|"; fast_pattern; nocase; classtype:misc-activity; sid:2036551; rev:2; metadata:created_at 2022_05_06, confidence Medium, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_05_09;)
Metadata
created at2022_05_06
confidenceMedium
signature severityInformational
tagDescription_Generated_By_Proofpoint_Nexus
updated at2022_05_09
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!