
Sonicwall Signatures


Go to All Categories list.

  FireEye GORAT Build ID IOC

Category: BACKDOOR      

Network detection rule that looks for specific response body content and HTTP server headers specified within Cobalt Strike malleable C2 profile. This is used as an attempt to blend in and provide a resemblance of legitimate network communications.

Relevant Information