alert syslog $EXTERNAL_NET any -> $HOME_NET any (msg:"[BASH] Ruby subproces execution"; content:"HISTORY"; content:"ruby"; content:"exec"; classtype:suspicious-command; program:bash|-bash|sh|-sh; sid:5002314; rev:1;)
-- Main.Sagan-Wiki-Add - 2015-10-21
New revisions of 5002314 will be below...