alert syslog $EXTERNAL_NET any -> $HOME_NET any (msg:"[BASH] ./a.out execution attempt"; content:"./a.out"; content:"HISTORY"; classtype: suspicious-command; reference: url,wiki.quadrantsec.com/bin/view/Main/5000000; program: bash|-bash|sh|-sh; sid:5000000; rev:4;)
-- Main.Sagan-Wiki-Add - 2015-10-21
New revisions of 5000000 will be below...