Skip to content

A network detection package for CVE-2020-16898 (Windows TCP/IP Remote Code Execution Vulnerability)

License

Notifications You must be signed in to change notification settings

corelight/CVE-2020-16898

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

21 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

"Bad Neighbor" Detection, CVE-2020-16898 (Windows TCP/IP RCE)

Summary:

A network detection package for CVE-2020-16898 (Windows TCP/IP Remote Code Execution Vulnerability)

References:

Notices raised :

CVE-2020-16898 exploit detected from %s. https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-16898#ID0EUGAC . Details from packet for reference: info=%s , options=%s

Usage, notes and recommendations:

  • To use against a pcap you already have zeek -Cr scripts/__load__.zeek your.pcap
  • This package will run in clustered or non clustered environments.

Feedback

  • As details emerge, we are keen to improve this package for the benefit of the community, please feel free to contact the author with any suggestions and feedback.

About

A network detection package for CVE-2020-16898 (Windows TCP/IP Remote Code Execution Vulnerability)

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published