""ET ATTACK_RESPONSE Possible MS CMD Shell opened on local system""

SID: 2008953

Revision: 9

Class Type: successful-admin

Metadata: created_at 2010_07_30, updated_at 2011_04_15

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: any

Destination Port: any

Flow: established

Contents:

  • Value: "Microsoft Windows " Depth: 20

  • Value: "Copyright 1985-20"

  • Value: "Microsoft Corp"

  • Value: "|0a 0a|"

Within:

PCRE:

Special Options:

source