Rule Category

FILE-EXECUTABLE -- Snort detected traffic targeting vulnerabilites that are found in or delivered through executable files, regardless of platform. In those instances, Snort is able to correct traffic that has been altered.

Alert Message

FILE-EXECUTABLE Portable Executable binary file magic detected

Rule Explanation

This rule looks for the magic file bytes for a Portable Executable.

What To Look For

This rule alerts on an attempt to download a Portable Executable file.

Known Usage

Public information/Proof of Concept available

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

MITRE::ATT&CK Framework::Enterprise::Execution::User Execution::Malicious File

CVE

None

Rule Vulnerability

No information provided

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.

None