alert syslog $EXTERNAL_NET any -> $HOME_NET any (msg:"[BASH] .bash_history access"; content:".bash_history"; content:"HISTORY"; classtype: suspicious-command; reference: url,wiki.quadrantsec.com/bin/view/Main/5000011; program: bash|-bash|sh|-sh; sid:5000011; rev:4;)
-- Main.Sagan-Wiki-Add - 2015-10-21
New revisions of 5000011 will be below...