Alert Message

No information provided

Rule Explanation

Per the SMB2 specification, the next command field, also called the "offset" or "chain offset" field allows for compounded requests. This is "a method of combining multiple SMB 2 Protocol requests or responses into a single transmission request for submission to the underlying transport." This rule will evaluate the field and compared it to the size of the payload and should alert when it detects an offset larger than the size of the payload. NOTE: This alert is related to detection of SMBGhost (CVE-2020-0796). That vulnerability can also be detected with sid 54217

What To Look For

This preprocessor rule will alert when it sees an offset to the next command in a chain of SMB2 commands that is larger than the size of the whole message

Known Usage

Attacks/Scans seen in the wild

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

None

Additional Links

Rule Vulnerability

No information provided

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.

None

MITRE ATT&CK Framework

Tactic: Execution

Technique: User Execution

For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org