TGI HUNT Suspicious Null in TLS SNI
Sourcetgreen/hunting
CreatedMarch 19, 2025
UpdatedMarch 19, 2025
Classificationattempted-admin
alert tls any any -> any [465,25,587] (msg:"TGI HUNT Suspicious Null in TLS SNI"; tls_sni; content:"|00|"; flow:established,to_server; ssl_state:client_hello; classtype:attempted-admin; sid:2610528; rev:1;)
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!