Techniques
Sample rules
Buffer Overflow Attempts
- source: sigma
- technicques:
- t1068
Description
Detects buffer overflow attempts in Unix system log files
Detection logic
condition: keywords
keywords:
- attempt to execute code on stack by
- 0bin0sh1
- AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
- stack smashing detected