🐾 - 🚨 VxWorks WDB Agent 👀 Version checked over RPC 🥷 - T1592.003
Sourcepawpatrules
CreatedMay 14, 2026
UpdatedMay 14, 2026
Classificationtargeted-activity
alert udp any any -> any any (msg:"🐾 - 🚨 VxWorks WDB Agent 👀 Version checked over RPC 🥷 - T1592.003"; flow:to_server, stateless; content:"|02 55 55 55 55 00 00 00 01 00 00 00 01|"; fast_pattern; content:"|ff ff 55 12|"; distance:16; content:"|3c 00 00 00 01 00 00 00 02|"; distance:3; content:"|00 00 00|"; endswith; target:dest_ip; reference:url,https://www.windriver.com/products/embedded/vxworks; reference:url,https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/vxworks/wdbrpc_version.rb; metadata:created_at 2026_05_14, updated_at 2026_05_14, signature_severity Major, attack_target OT, affected_product VxWorks, mitre_tactic_id TA0043, mitre_tactic_name Reconnaissance, mitre_technique_id T1592_002, mitre_technique_name Gather_Victim_Host_Information-Firmware; sid:3321483; rev:1; classtype:targeted-activity;)
References
Metadata
created at2026_05_14
updated at2026_05_14
signature severityMajor
attack targetOT
affected productVxWorks
mitre tactic idTA0043
mitre tactic nameReconnaissance
mitre technique idT1592_002
mitre technique nameGather_Victim_Host_Information-Firmware
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!