TOOLS [PTsecurity] Sliver C2 HTTP Polling (English)

SID: 10008548Rev: 333 views
History
Sourceptrules/open
CreatedSeptember 4, 2025
UpdatedSeptember 4, 2025
Classificationattempted-admin
alert http any any -> any any (msg:"TOOLS [PTsecurity] Sliver C2 HTTP Polling (English)"; flow:established, from_server; http.header; content:"Content-Type|3A| text/plain|3B| charset=utf-8|0d 0a|"; nocase; content:!"Content-Encoding"; nocase; http.response_body; pcre:"/^(?:[A-Z]{2,20}\s?){40,}$/Q"; flowbits:isset, Sliver.HTTP.Encoders; threshold:type limit, track by_src, count 1, seconds 300; reference:url, github.com/BishopFox/sliver; reference:url, rules.ptsecurity.com; classtype:attempted-admin; sid:10008548; rev:3;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!