""ET ATTACK_RESPONSE Windows 7 CMD Shell from Local System""

SID: 2012690

Revision: 1

Class Type: successful-admin

Metadata: created_at 2011_04_17, updated_at 2011_04_17

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: any

Destination Port: any

Flow: established

Contents:

  • Value: "Microsoft Windows [Version " Depth: 30

  • Value: "Copyright (c)"

  • Value: "Microsoft Corp"

Within:

PCRE:

Special Options:

source