2024-12-21 01:02:34 +01:00
[
2025-02-26 00:26:24 +00:00
{
"category" : "LFI" ,
"pattern" : "@lt 1"
} ,
{
"category" : "LFI" ,
"pattern" : "@lt 1"
} ,
{
"category" : "LFI" ,
"pattern" : "@rx (?i)(?:[/x5c]|%(?:2(?:f|5(?:2f|5c|c(?:1%259c|0%25af))|%46)|5c|c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|(?:bg%q|(?:e|f(?:8%8)?0%8)0%80%a)f|u(?:221[5-6]|EFC8|F025|002f)|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|1u)|0x(?:2f|5c))(?:.(?:%0[0-1]|?)?|?.?|%(?:2(?:(?:5(?:2|c0%25a))?e|%45)|c0(?:.|%[25-6ae-f]e)|u(?:(?:ff0|002)e|2024)|%32(?:%(?:%6|4)5|E)|(?:e|f(?:(?:8|c%80)%8)?0%8)0%80%ae)|0x2e){2,3}(?:[/x5c]|%(?:2(?:f|5(?:2f|5c|c(?:1%259c|0%25af))|%46)|5c|c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|(?:bg%q|(?:e|f(?:8%8)?0%8)0%80%a)f|u(?:221[5-6]|EFC8|F025|002f)|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|1u)|0x(?:2f|5c))"
} ,
{
"category" : "LFI" ,
"pattern" : "@rx (?:(?:^|[x5c/;]).{2,3}[x5c/;]|[x5c/;].{2,3}(?:[x5c/;]|$))"
} ,
{
"category" : "LFI" ,
"pattern" : "@pmFromFile lfi-os-files.data"
} ,
{
"category" : "LFI" ,
"pattern" : "@pmFromFile restricted-files.data"
} ,
{
"category" : "LFI" ,
"pattern" : "@lt 2"
} ,
{
"category" : "LFI" ,
"pattern" : "@lt 2"
} ,
{
"category" : "LFI" ,
"pattern" : "@pmFromFile lfi-os-files.data"
} ,
{
"category" : "LFI" ,
"pattern" : "@lt 3"
} ,
{
"category" : "LFI" ,
"pattern" : "@lt 3"
} ,
{
"category" : "LFI" ,
"pattern" : "@lt 4"
} ,
{
"category" : "LFI" ,
"pattern" : "@lt 4"
} ,
2025-02-02 00:27:06 +00:00
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-02 00:27:06 +00:00
} ,
2025-01-31 00:25:27 +00:00
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 0"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 1"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@rx ^.*$"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "!@rx (?:URLENCODED|MULTIPART|XML|JSON)"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 1"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "!@rx (?:URLENCODED|MULTIPART|XML|JSON)"
2025-01-21 00:25:04 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@eq 100"
2025-01-21 00:25:04 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@rx ^[a-f]*([0-9])[a-f]*([0-9])"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "!@lt %{tx.sampling_percentage}"
2025-02-04 00:25:09 +00:00
} ,
2025-02-08 00:25:04 +00:00
{
2025-02-24 00:27:16 +00:00
"category" : "INITIALIZATION" ,
"pattern" : "@lt %{tx.blocking_paranoia_level}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "DETECTION" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 1"
2025-02-08 00:25:04 +00:00
} ,
2025-02-04 00:25:09 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "DETECTION" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 1"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "DETECTION" ,
"pattern" : "@pmFromFile scanners-user-agents.data"
2025-01-06 00:28:11 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "DETECTION" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 2"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "DETECTION" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 2"
2024-12-21 01:02:34 +01:00
} ,
2025-01-29 00:25:14 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "DETECTION" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 3"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "DETECTION" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 3"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "DETECTION" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 4"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "DETECTION" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 4"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 1"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 1"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@rx _(?:$$ND_FUNC$$_|_js_function)|(?:beval|new[sv]+Function[sv]*)(|String.fromCharCode|function(){|this.constructor|module.exports=|([sv]*[^0-9A-Z_a-z]child_process[^0-9A-Z_a-z][sv]*)|process(?:.(?:(?:a(?:ccess|ppendfile|rgv|vailability)|c(?:aveats|h(?:mod|own)|(?:los|opyfil)e|p|reate(?:read|write)stream)|ex(?:ec(?:file)?|ists)|f(?:ch(?:mod|own)|data(?:sync)?|s(?:tat|ync)|utimes)|inodes|l(?:chmod|ink|stat|utimes)|mkd(?:ir|temp)|open(?:dir)?|r(?:e(?:ad(?:dir|file|link|v)?|name)|m)|s(?:pawn(?:file)?|tat|ymlink)|truncate|u(?:n(?:link|watchfile)|times)|w(?:atchfile|rite(?:file|v)?))(?:sync)?(?:.call)?(|binding|constructor|env|global|main(?:Module)?|process|require)|[[\"'`](?:(?:a(?:ccess|ppendfile|rgv|vailability)|c(?:aveats|h(?:mod|own)|(?:los|opyfil)e|p|reate(?:read|write)stream)|ex(?:ec(?:file)?|ists)|f(?:ch(?:mod|own)|data(?:sync)?|s(?:tat|ync)|utimes)|inodes|l(?:chmod|ink|stat|utimes)|mkd(?:ir|temp)|open(?:dir)?|r(?:e(?:ad(?:dir|file|link|v)?|name)|m)|s(?:pawn(?:file)?|tat|ymlink)|truncate|u(?:n(?:link|watchfile)|times)|w(?:atchfile|rite(?:file|v)?))(?:sync)?|binding|constructor|env|global|main(?:Module)?|process|require)[\"'`]])|(?:binding|constructor|env|global|main(?:Module)?|process|require)[|console(?:.(?:debug|error|info|trace|warn)(?:.call)?(|[[\"'`](?:debug|error|info|trace|warn)[\"'`]])|require(?:.(?:resolve(?:.call)?(|main|extensions|cache)|[[\"'`](?:(?:resolv|cach)e|main|extensions)[\"'`]])"
2025-02-24 00:27:16 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@rx (?:close|exists|fork|(?:ope|spaw)n|re(?:ad|quire)|w(?:atch|rite))[sv]*("
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@pmFromFile ssrf.data"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@rx (?:__proto__|constructors*(?:.|[)s*prototype)"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@rx Process[sv]*.[sv]*spawn[sv]*("
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@rx while[sv]*([sv(]*(?:!+(?:false|null|undefined|NaN|[+-]?0|\"{2}|'{2}|`{2})|(?:!!)*(?:(?:t(?:rue|his)|[+-]?(?:Infinity|[1-9][0-9]*)|new [A-Za-z][0-9A-Z_a-z]*|window|String|(?:Boolea|Functio)n|Object|Array)b|{.*}|[.*]|\"[^\"]+\"|'[^']+'|`[^`]+`)).*)"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@rx ^data:(?:(?:*|[^!-\"(-),/:-?[-]{}]+)/(?:*|[^!-\"(-),/:-?[-]{}]+)|*)(?:[sv]*;[sv]*(?:charset[sv]*=[sv]*\"?(?:iso-8859-15?|utf-8|windows-1252)b\"?|(?:[^sv -\"(-),/:-?[-]c{}]|c(?:[^!-\"(-),/:-?[-]h{}]|h(?:[^!-\"(-),/:-?[-]a{}]|a(?:[^!-\"(-),/:-?[-]r{}]|r(?:[^!-\"(-),/:-?[-]s{}]|s(?:[^!-\"(-),/:-?[-]e{}]|e[^!-\"(-),/:-?[-]t{}]))))))[^!-\"(-),/:-?[-]{}]*[sv]*=[sv]*[^!(-),/:-?[-]{}]+);?)*(?:[sv]*,[sv]*(?:(?:*|[^!-\"(-),/:-?[-]{}]+)/(?:*|[^!-\"(-),/:-?[-]{}]+)|*)(?:[sv]*;[sv]*(?:charset[sv]*=[sv]*\"?(?:iso-8859-15?|utf-8|windows-1252)b\"?|(?:[^sv -\"(-),/:-?[-]c{}]|c(?:[^!-\"(-),/:-?[-]h{}]|h(?:[^!-\"(-),/:-?[-]a{}]|a(?:[^!-\"(-),/:-?[-]r{}]|r(?:[^!-\"(-),/:-?[-]s{}]|s(?:[^!-\"(-),/:-?[-]e{}]|e[^!-\"(-),/:-?[-]t{}]))))))[^!-\"(-),/:-?[-]{}]*[sv]*=[sv]*[^!(-),/:-?[-]{}]+);?)*)*"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@lt 2"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@lt 2"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@rx (?i)((?:a(?:cap|f[ps]|ttachment)|b(?:eshare|itcoin|lob)|c(?:a(?:llto|p)|id|vs|ompress.(?:zlib|bzip2))|d(?:a(?:v|ta)|ict|n(?:s|tp))|e(?:d2k|xpect)|f(?:(?:ee)?d|i(?:le|nger|sh)|tps?)|g(?:it|o(?:pher)?|lob)|h(?:323|ttps?)|i(?:ax|cap|(?:ma|p)ps?|rc[6s]?)|ja(?:bbe)?r|l(?:dap[is]?|ocal_file)|m(?:a(?:ilto|ven)|ms|umble)|n(?:e(?:tdoc|ws)|fs|ntps?)|ogg|p(?:aparazzi|h(?:ar|p)|op(?:2|3s?)|r(?:es|oxy)|syc)|r(?:mi|sync|tm(?:f?p)?|ar)|s(?:3|ftp|ips?|m(?:[bs]|tps?)|n(?:ews|mp)|sh(?:2(?:.(?:s(?:hell|(?:ft|c)p)|exec|tunnel))?)?|vn(?:+ssh)?)|t(?:e(?:amspeak|lnet)|ftp|urns?)|u(?:dp|nreal|t2004)|v(?:entrilo|iew-source|nc)|w(?:ebcal|ss?)|x(?:mpp|ri)|zip)://(?:[0-9]{10}|(?:0x[0-9a-f]{2}.){3}0x[0-9a-f]{2}|0x(?:[0-9a-f]{8}|[0-9a-f]{16})|(?:0{1,4}[0-9]{1,3}.){3}0{1,4}[0-9]{1,3}|[0-9]{1,3}.(?:[0-9]{1,3}.[0-9]{5}|[0-9]{8})|(?:x5cx5c[-0-9a-z].?_?)+|[[0-:a-f]+(?:[.0-9]+|%[0-9A-Z_a-z]+)?]|[a-z][--.0-9A-Z_a-z]{1,255}:[0-9]{1,5}(?:#?[sv]*&?@(?:(?:[0-9]{1,3}.){3}[0-9]{1,3}|[a-z][--.0-9A-Z_a-z]{1,255}):[0-9]{1,5}/?)+|[.0-9]{0,11}(?:xe2(?:x91[xa0-xbf]|x92[x80-xbf]|x93[x80-xa9xab-xbf])|xe3x80x82)+))"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@rx [s*constructors*]"
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@rx @{.*}"
2025-01-29 00:25:14 +00:00
} ,
2024-12-21 01:02:34 +01:00
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@lt 3"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@lt 3"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@lt 4"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "GENERIC" ,
"pattern" : "@lt 4"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EXCEPTIONS" ,
"pattern" : "@streq GET /"
2025-01-27 00:26:20 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EXCEPTIONS" ,
"pattern" : "@ipMatch 127.0.0.1,::1"
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EXCEPTIONS" ,
"pattern" : "@ipMatch 127.0.0.1,::1"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EXCEPTIONS" ,
"pattern" : "@endsWith (internal dummy connection)"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EXCEPTIONS" ,
"pattern" : "@rx ^(?:GET /|OPTIONS *) HTTP/[12].[01]$"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "@lt 1"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "@lt 1"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "@rx ^(?i:file|ftps?|https?)://(?:d{1,3}.d{1,3}.d{1,3}.d{1,3})"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "@rx (?i)(?:bincludes*([^)]*|mosConfig_absolute_path|_CONF[path]|_SERVER[DOCUMENT_ROOT]|GALLERY_BASEDIR|path[docroot]|appserv_root|config[root_dir])=(?:file|ftps?|https?)://"
2025-02-24 00:27:16 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "@rx ^(?i:file|ftps?|https?).*??+$"
2025-02-24 00:27:16 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "@lt 2"
2025-02-24 00:27:16 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "@lt 2"
2025-02-24 00:27:16 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "@rx (?i)(?:(?:url|jar):)?(?:a(?:cap|f[ps]|ttachment)|b(?:eshare|itcoin|lob)|c(?:a(?:llto|p)|id|vs|ompress.(?:zlib|bzip2))|d(?:a(?:v|ta)|ict|n(?:s|tp))|e(?:d2k|xpect)|f(?:(?:ee)?d|i(?:le|nger|sh)|tps?)|g(?:it|o(?:pher)?|lob)|h(?:323|ttps?)|i(?:ax|cap|(?:ma|p)ps?|rc[6s]?)|ja(?:bbe)?r|l(?:dap[is]?|ocal_file)|m(?:a(?:ilto|ven)|ms|umble)|n(?:e(?:tdoc|ws)|fs|ntps?)|ogg|p(?:aparazzi|h(?:ar|p)|op(?:2|3s?)|r(?:es|oxy)|syc)|r(?:mi|sync|tm(?:f?p)?|ar)|s(?:3|ftp|ips?|m(?:[bs]|tps?)|n(?:ews|mp)|sh(?:2(?:.(?:s(?:hell|(?:ft|c)p)|exec|tunnel))?)?|vn(?:+ssh)?)|t(?:e(?:amspeak|lnet)|ftp|urns?)|u(?:dp|nreal|t2004)|v(?:entrilo|iew-source|nc)|w(?:ebcal|ss?)|x(?:mpp|ri)|zip)://(?:[^@]+@)?([^/]*)"
2025-02-24 00:27:16 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "!@endsWith .%{request_headers.host}"
2025-02-24 00:27:16 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "@rx (?i)(?:(?:url|jar):)?(?:a(?:cap|f[ps]|ttachment)|b(?:eshare|itcoin|lob)|c(?:a(?:llto|p)|id|vs|ompress.(?:zlib|bzip2))|d(?:a(?:v|ta)|ict|n(?:s|tp))|e(?:d2k|xpect)|f(?:(?:ee)?d|i(?:le|nger|sh)|tps?)|g(?:it|o(?:pher)?|lob)|h(?:323|ttps?)|i(?:ax|cap|(?:ma|p)ps?|rc[6s]?)|ja(?:bbe)?r|l(?:dap[is]?|ocal_file)|m(?:a(?:ilto|ven)|ms|umble)|n(?:e(?:tdoc|ws)|fs|ntps?)|ogg|p(?:aparazzi|h(?:ar|p)|op(?:2|3s?)|r(?:es|oxy)|syc)|r(?:mi|sync|tm(?:f?p)?|ar)|s(?:3|ftp|ips?|m(?:[bs]|tps?)|n(?:ews|mp)|sh(?:2(?:.(?:s(?:hell|(?:ft|c)p)|exec|tunnel))?)?|vn(?:+ssh)?)|t(?:e(?:amspeak|lnet)|ftp|urns?)|u(?:dp|nreal|t2004)|v(?:entrilo|iew-source|nc)|w(?:ebcal|ss?)|x(?:mpp|ri)|zip)://(?:[^@]+@)?([^/]*)"
2025-02-24 00:27:16 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
"pattern" : "!@endsWith .%{request_headers.host}"
} ,
{
"category" : "RFI" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 3"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 3"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 4"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RFI" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 4"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 1"
2025-02-24 00:27:16 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 1"
2025-02-24 00:27:16 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx (?:get|post|head|options|connect|put|delete|trace|track|patch|propfind|propatch|mkcol|copy|move|lock|unlock)s+[^s]+s+http/d"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx [rn]W*?(?:content-(?:type|length)|set-cookie|location):s*w"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx (?:bhttp/d|<(?:html|meta)b)"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx [nr]"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx [nr]"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx [nr]+(?:s|location|refresh|(?:set-)?cookie|(?:x-)?(?:forwarded-(?:for|host|server)|host|via|remote-ip|remote-addr|originating-IP))s*:"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx [nr]"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx ^[^:()&|!<>~]*)s*(?:((?:[^,()=&|!<>~]+[><~]?=|s*[&!|]s*(?:)|()?s*)|)s*(s*[&|!]s*|[&!|]s*([^()=&|!<>~]+[><~]?=[^:()&|!<>~]*)"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx ^[^sv,;]+[sv,;].*?(?:application/(?:.++)?json|(?:application/(?:soap+)?|text/)xml)"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx unix:[^|]*|"
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@lt 2"
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@lt 2"
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx [nr]"
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx ^[^sv,;]+[sv,;].*?b(?:((?:tex|multipar)t|application)|((?:audi|vide)o|image|cs[sv]|(?:vn|relate)d|p(?:df|lain)|json|(?:soa|cs)p|x(?:ml|-www-form-urlencoded)|form-data|x-amf|(?:octe|repor)t|stream)|([+/]))b"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@lt 3"
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 3"
2025-01-26 00:25:41 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@gt 0"
2025-01-26 00:25:41 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx ."
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@gt 1"
2025-01-22 00:25:38 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "ATTACK" ,
2025-02-26 00:26:24 +00:00
"pattern" : "@rx TX:paramcounter_(.*)"
2025-01-22 00:25:38 +00:00
} ,
2025-01-26 00:25:41 +00:00
{
2025-02-24 00:27:16 +00:00
"category" : "ATTACK" ,
2025-02-26 00:26:24 +00:00
"pattern" : "@rx (][^]]+$|][^]]+[)"
2025-01-26 00:25:41 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "ATTACK" ,
2025-02-26 00:26:24 +00:00
"pattern" : "@lt 4"
2025-01-26 00:25:41 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "ATTACK" ,
2025-02-26 00:26:24 +00:00
"pattern" : "@lt 4"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-24 00:27:16 +00:00
"category" : "ATTACK" ,
2025-02-26 00:26:24 +00:00
"pattern" : "@rx ["
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 1"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 1"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx (?:<?(?:[^x]|x[^m]|xm[^l]|xml[^s]|xml$|$)|<?php|[(?:/|x5c)?php])"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx .*.ph(?:pd*|tml|ar|ps|t|pt).*$"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@pmFromFile php-config-directives.data"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@pm ="
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@pmFromFile php-variables.data"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx (?i)php://(?:std(?:in|out|err)|(?:in|out)put|fd|memory|temp|filter)"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx (?:bzip2|expect|glob|ogg|(?:ph|r)ar|ssh2(?:.(?:s(?:hell|(?:ft|c)p)|exec|tunnel))?|z(?:ip|lib))://"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@pmFromFile php-function-names-933150.data"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx (?i)b(?[\"']*(?:assert(?:_options)?|c(?:hr|reate_function)|e(?:val|x(?:ec|p))|file(?:group)?|glob|i(?:mage(?:gif|(?:jpe|pn)g|wbmp|xbm)|s_a)|md5|o(?:pendir|rd)|p(?:assthru|open|rev)|(?:read|tmp)file|un(?:pac|lin)k|s(?:tat|ubstr|ystem))(?:/(?:*.**/|/.*)|#.*[sv]|\")*[\"']*)?[sv]*(.*)"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx [oOcC]:d+:\".+?\":d+:{.*}"
2025-01-26 00:25:41 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx $+(?:[a-zA-Z_x7f-xff][a-zA-Z0-9_x7f-xff]*|s*{.+})(?:s|[.+]|{.+}|/*.**/|//.*|#.*)*(.*)"
2025-01-26 00:25:41 +00:00
} ,
2025-01-22 00:25:38 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx (?:((?:.+)(?:[\"'][-0-9A-Z_a-z]+[\"'])?(.+|[^)]*string[^)]*)[sv\"'--.0-9A-[]_a-{}]+([^)]*)|(?:[[0-9]+]|{[0-9]+}|$[^(-),.-/;x5c]+|[\"'][-0-9A-Zx5c_a-z]+[\"'])(.+));"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@lt 2"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@lt 2"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@pmFromFile php-function-names-933151.data"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@pm ("
2025-01-22 00:25:38 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@lt 3"
2025-01-19 00:27:39 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@lt 3"
2025-01-19 00:27:39 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx AUTH_TYPE|HTTP_(?:ACCEPT(?:_(?:CHARSET|ENCODING|LANGUAGE))?|CONNECTION|(?:HOS|USER_AGEN)T|KEEP_ALIVE|(?:REFERE|X_FORWARDED_FO)R)|ORIG_PATH_INFO|PATH_(?:INFO|TRANSLATED)|QUERY_STRING|REQUEST_URI"
2025-01-19 00:27:39 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx (?i)b(?:a(?:bs|s(?:in|sert(?:_options)?))|basename|c(?:h(?:eckdate|r(?:oot)?)|o(?:(?:mpac|(?:nsta|u)n)t|py|sh?)|r(?:eate_function|ypt)|urrent)|d(?:ate|e(?:coct|fined?)|ir)|e(?:nd|val|x(?:ec|p(?:lode)?|tract))|f(?:ile(?:(?:[acm]tim|inod|siz|typ)e|group|owner|perms)?|l(?:o(?:ck|or)|ush))|glob|h(?:ash|eader)|i(?:date|m(?:age(?:gif|(?:jpe|pn)g|wbmp|xbm)|plode)|s_a)|key|l(?:ink|og)|m(?:a(?:il|x)|d5|in)|n(?:ame|ext)|o(?:pendir|rd)|p(?:a(?:ck|ss(?:thru)?)|i|o(?:pen|w)|rev)|r(?:an(?:d|ge)|e(?:(?:adfil|nam)e|set)|ound)|s(?:(?:erializ|huffl)e|in|leep|(?:or|ta)t|ubstr|y(?:mlink|s(?:log|tem)))|t(?:an|(?:im|mpfil)e|ouch|rim)|u(?:cfirst|n(?:lin|pac)k)|virtual)(?:[sv]|/*.**/|(?:#|//).*)*(.*)"
2025-01-27 00:26:20 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx .*.(?:phpd*|phtml)..*$"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@pm ?>"
2025-01-27 00:26:20 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
"pattern" : "@rx (?:((?:.+)(?:[\"'][-0-9A-Z_a-z]+[\"'])?(.+|[^)]*string[^)]*)[sv\"'--.0-9A-[]_a-{}]+([^)]*)|(?:[[0-9]+]|{[0-9]+}|$[^(-),.-/;x5c]+|[\"'][-0-9A-Zx5c_a-z]+[\"'])(.+))(?:;|$)?"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
2025-02-09 00:27:59 +00:00
"pattern" : "@lt 4"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "PHP" ,
2025-02-09 00:27:59 +00:00
"pattern" : "@lt 4"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
2025-02-09 00:27:59 +00:00
"pattern" : "@lt 1"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
2025-02-09 00:27:59 +00:00
"pattern" : "@lt 1"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
"pattern" : "@rx (?i:.cookieb.*?;W*?(?:expires|domain)W*?=|bhttp-equivW+set-cookieb)"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
"pattern" : "@rx ^(?:jsessionid|aspsessionid|asp.net_sessionid|phpsession|phpsessid|weblogicsession|session_id|session-id|cfid|cftoken|cfsid|jservsession|jwsession)$"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
"pattern" : "@rx ^(?:ht|f)tps?://(.*?)/"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
"pattern" : "!@endsWith %{request_headers.host}"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
"pattern" : "@rx ^(?:jsessionid|aspsessionid|asp.net_sessionid|phpsession|phpsessid|weblogicsession|session_id|session-id|cfid|cftoken|cfsid|jservsession|jwsession)$"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
"pattern" : "@eq 0"
2025-01-18 00:24:13 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 2"
2025-01-09 00:26:35 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 2"
2025-01-06 00:28:11 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
"pattern" : "@lt 3"
2025-01-13 00:29:11 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
"pattern" : "@lt 3"
2025-01-13 00:29:11 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
"pattern" : "@lt 4"
2025-01-13 00:29:11 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "FIXATION" ,
"pattern" : "@lt 4"
2025-01-13 00:29:11 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@lt 1"
2025-01-07 18:00:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@lt 1"
2025-01-27 00:26:20 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)(?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[nr;`{]|||?|&&?|$(?:((?|{)|[<>](|([sv]*))[sv]*(?:[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*[sv]*[\"']*(?:[\"'-+--9?A-]_a-z|]+/)?[\"'x5c]*(?:7[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[arx])?|(?:(?:b[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z|x)[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z|h[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?u[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p)[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[sv&),<>|].*|[ckz][\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?s[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?h|d[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?f|e[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:n[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?v|s[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?h)|f[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[dg]|g[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:c[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?c[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:[&,<>|]|(?:[--.0-9A-Z_a-z][\"'[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#*-0-9?-@_a-{]*)?x5c?)+[sv&,<>|]).*|p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?g)|i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?r[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?b|l[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:s|z[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:4|[sv&),<>|].*))|p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:h[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[sv&),<>|].*|w[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d|x[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z)|r[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?c(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[sv&),<>|].*)?|s[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:c[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p|(?:e[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d|(?:s[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?)?h)[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[sv&),<>|].*|v[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?n)|u[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p|w[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?3[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m)b"
2025-01-27 00:26:20 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)(?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[nr;`{]|||?|&&?|$(?:((?|{)|[<>](|([sv]*))[sv]*(?:[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*[sv]*[\"']*(?:[\"'-+--9?A-]_a-z|]+/)?[\" ' x 5 c ] * ( ? : ( ? : H E A D | P O S T | y ( ? : a r n | e l p ) ) [ s v & ) < > | ] | a ( ? : d d ( ? : g r o u p | u s e r ) | g e t t y | l ( ? : i a s | p i n e ) [ s v & ) < > | ] | n s i b l e - p l a y b o o k | p t ( ? : - g e t | i t u d e [ s v & ) < > | ] ) | r ( ? : c h [ s v & ) < > | ] | i a 2 c ) | s ( ? : c i i ( ? : - x f r | 85 ) | p e l l ) | t o b m | x e l ) | b ( ? : a ( ? : s ( ? : e ( ? : 32 | 64 | n ( ? : a m e [ s v & ) < > | ] | c ) ) | h [ s v & ) < > | ] ) | t c h [ s v & ) < > | ] ) | l k i d | p f t r a c e | r ( ? : e a k s w | i d g e [ s v & ) < > | ] ) | s d ( ? : c a t | i f f | t a r ) | u ( ? : i l t i n | n ( ? : d l e r [ s v & ) < > | ] | z i p 2 ) | s ( ? : c t l | y b o x ) ) | y ( ? : e b u g | o b u ) | z ( ? : c ( ? : a t | m p ) | d i f f | e ( ? : g r e p | x e ) | f ? g r e p | i p 2 ( ? : r e c o v e r ) ? | l e s s | m o r e ) ) | c ( ? : a ( ? : n c e l | p s h ) [ s v & ) < > | ] | e r t b o t | h ( ? : a t t r | ( ? : d i r | r o o t ) [ s v & ) < > | ] | e c k _ ( ? : b y _ s s h | c u p s | l o g | m e m o r y | r a i d | s ( ? : s l _ c e r t | t a t u s f i l e ) ) | ( ? : f l a g | p a s ) s | g ( ? : p a s s w d | r p ) | m o d | o ( ? : o m | w n ) | s h ) | l a n g ( ? : [ s v & ) < > | ] | + + ) | o ( ? : ( ? : b | p r o ) c | l u m n [ s v & ) < > | ] | m ( ? : m ( ? : a n d [ s v & ) < > | ] ) ? | p ( ? : o s e r | r e s s ) [ s v & ) < > | ] ) | w ( ? : s a y | t h i n k ) ) | p ( ? : a n | i o | u l i m i t ) | r ( ? : a s h [ s v & ) < > | ] | o n ( ? : t a b ) ? ) | s ( ? : p l i t | v t o o l ) | u ( ? : p s f i l t e r | r l [ s v & ) < > | ] ) ) | d ( ? : ( ? : a ( ? : s h | t e ) | i ( ? : a l o g | f f ) ) [ s v & ) < > | ] | h c l i e n t | m ( ? : e s g | i d e c o d e | s e t u p ) | o ( ? : a s | ( ? : c k e r | n e ) [ s v & ) < > | ] | s b o x ) | p k g | v i p s ) | e ( ? : 2 f s c k | ( ? : a s y _ i n s t a l | v a ) l | c h o [ s v & ) < > | ] | f a x | g r e p | m a c s | n ( ? : d ( ? : i f | s w ) | v - u p d a t e ) | s a c | x ( ? : e c [ s v & ) < > | ] | i f t o o l | p ( ? : ( ? : a n d | ( ? : e c | o r ) t ) [ s v & ) < > | ] | r ) ) ) | f ( ? : a c t e r | ( ? : e t c h | l o c k | u n c t i o n ) [ s v & ) < > | ] | g r e p | i ( ? : l e ( ? : [ s v & ) < > | ] | t e s t ) | ( ? : n ( ? : d | g e r ) | s h ) [ s v & ) < > | ] ) | o ( ? : l d [ s v & ) < > | ] | r e a c h ) | p i n g | t p ( ? : s t a t s | w h o ) ) | g ( ? : a w k [ s v & ) < > | ] | c o r e | e ( ? : n i ( ? : e [ s v & ) < > | ] | s o i m a g e ) | t f a c l [ s v & ) < > | ] ) | h c i | i ( ? : m p [ s v & ) < > | ] | n s h ) | r ( ? : e p [ s v & ) < > | ] | o u p ( ? : [ s v & ) < > | ] | m o d ) ) | t e s t e r | u n z i p | z ( ? : c a t | e x e | i p ) ) | h ( ? : ( ? : a s h | i ( ? : g h l i g h t | s t o r y ) ) [ s v & ) < > | ] | e ( ? : a d [ s v & ) < > | ] | x d u m p ) | o s t ( ? : i d | n a m e ) | p i n g 3 | t ( ? : d i g e s t | o p | p a s s w d ) ) | i ( ? : c o n v | f ( ? : c o n f i g | t o p ) | n s t a l l [ s v & ) < > | ] | o n i c e | p ( ? : 6 ? t a b l e s | c o n f i g ) | s p e l l ) | j ( ? : a v a [ s v & ) < > | ] | e x e c | o ( ? : ( ? : b s | i n ) [ s v & ) < > | ] | u r n a l c t l ) | r u n s c r i p t ) | k ( ? : i l l ( ? : [ s v & ) < > | ] | a l l ) | n i f e [ s v & ) < > | ] | s s h e l l ) | l ( ? : a ( ? : s t ( ? : [ s v & ) < > | ] | c o m m | l o g ( ? : i n ) ? ) | t e x [ s v & ) < > | ] ) | d c o n f i g | e s s ( ? : [ s v & ) < > | ] | e c h o | ( ? : f i l | p i p ) e ) | f t p ( ? : g e t ) ? | ( ? : i n k s | y n x ) [ s v & ) < > | ] | o ( ? : ( ? : c a ( ? : l | t e ) | o k ) [ s v & ) < > | ] | g ( ? : i n c t l | ( ? : n a m | s a v ) e ) | s e t u p ) | s ( ? : - F | b _ r e l e a s e | c p u | h w | m o d | o f | p c i | u s b ) | t r a c e | u a ( ? : l a ) ? t e x | w p - ( ? : d ( ? : o w n l o a d | u m p ) | m i r r o r | r e q u e s t ) | z ( ? : 4 c ( ? : a t ) ? | c ( ? : a t | m p ) | d i f f | [ e - f ] ? g r e p | l e s s | m ( ? : a ( ? : d e c | i n f o ) ? | o r e ) ) ) | m ( ? : a ( ? : i l ( ? : [ s v & ) < > q | ] | x [ s v & ) < > | ] ) | k e [ s v & ) < > | ] | s t e r . p a s s w d | w k ) | k ( ? : d i r [ s v & ) < > | ] | f i f o | n o d | t e m p ) | l o c a t e | o ( ? : ( ? : r e | u n t ) [ s v & ) < > | ] | s q u i t t o ) | s g ( ? : a t t r i b | c ( ? : a t | o n v ) | f i l t e r | m e r g e | u n i q ) | u t t [ s v & ) < > | ] | y s q l ( ? : a d m i n | d u m p ( ? : s l o w ) ? | h o t c o p y | s h o w ) ? ) | n ( ? : a ( ? : n o [ s v & ) < > | ] | s m | w k ) | c ( ? : . ( ? : o p e n b s d | t r a d i t i o n a l ) | a t ) | e ( ? : o f e t c h | t ( ? : ( ? : c | s t ) a t | k i t - f t p | p l a n ) ) | ( ? : i c e | u l l ) [ s v & ) < > | ] | m a p | o ( ? : d e [ s v & ) < > | ] | h u p ) | p i n g | r o f f | s ( ? : e n t e r | l o o k u p | t a t ) ) | o ( ? : c t a v e [ s v & ) < > | ] | n i n t r | p ( ? : e n ( ? : s s l | v ( ? : p n | t ) ) | k g ) ) | p ( ? : a ( ? : ( ? : c m a n | r t e d | t c h ) [ s v & ) < > | ] | s ( ? : s w d | t e [ s v & ) < > | ] ) ) | d ( ? : f ( ? : l a ) ? t e x | k s h ) | e r ( ? : f | l ( ? : 5 | s h ) ? | m s [ s v & ) < > | ] ) | ( ? : f t | g r e ) p | h p ( ? : - c g i | [ 57 ] ) | i ( ? : ( ? : c o | n g ) [ s v & ) < > | ] | d s t a t | g z ) | k ( ? : e x e c | g _ ? i n f o | i l l ) | o p d | r i n t ( ? : e n v | f [ s v & ) < > | ] ) | s ( ? : e d | f t p | q l ) | t a r ( ? : d i f f | g r e p ) ? | u ( ? : p p e t [ s v & ) < > | ] | s h d ) | w d . d b | y t h o n [ ^ s v ] ) | r ( ? : a k ( ? : e [ s v & ) < > | ] | u ) | b a s h | e ( ? : a ( ? : d e l f | l p a t h ) | ( ? : d c a r p e t | n a m e | p ( ? : e a t | l a c e ) ) [ s v & ) < > | ] | s t i c ) | l ( ? : o g i n | w r a p ) | m ( ? : d i r [ s v & ) < > | ] | u s e r ) | n a n o | o u t e [ s v & ) < > | ] | p m ( ? : d b | ( ? : q u e r | v e r i f ) y ) | s y n c | u ( ? : b y [ ^ s v ] | n - ( ? : m a i l c a p | p a r t s ) ) | v i ( ? : e w | m ) ) | s ( ? : ( ? : a s h | n a p ) [ s v & ) < > | ] | c ( ? : h e d | r ( ? : e e n | i p t ) [ s v & ) < > | ] ) | d i f f | e ( ? : ( ? : l f | r v i c e ) [ s v & ) < > | ] | n d m a i l | t ( ? : a r c h | e n v | f a c l [ s v & ) < > | ] | s i d ) ) | f t p | h ( ? : . d i s t r i b | ( ? : a d o w | e l l s ) [ s v & ) < > | ] | u ( ? : f | t d o w n [ s v & ) < > | ] ) ) | l ( ? : e e p [ s v & ) < > | ] | s h ) | m b c l i e n t | o ( ? : c a t | e l i m | ( ? : r t | u r c e ) [ s v & ) < > | ] ) | p ( ? : l i t [ s v & ) < > | ] | w d . d b ) | q l i t e 3 | s h ( ? : - k e y ( ? : g e | s c a ) n | p a s s ) | t ( ? : a r t - s t o p - d a e m o n | d ( ? : b u f | e r r | i n | o u t ) | r ( ? : a c e | i n g s [ s v & ) < > | ] ) ) | u d o | y s ( ? : c t l | t e m ( ? : c t l | d - r e s o l v e ) ) ) | t ( ? : a ( ? : i l [ s v & ) < > f | ] | s k ( ? : [ s v & ) < > | ] | s e t ) ) | c ( ? : l ? s h | p ( ? : d u m p | i n g | t r a c e r o u t e ) ) | e l n e t | f t p | i m e ( ? : ( ? : o u t ) ? [ s v & ) < > | ] | d a t e c t l ) | m u x | o u c h [ s v & ) < > | ] | r ( ? : a c e r o u t e 6 ? | o f f ) | s h a r k ) | u ( ? : l i m i t [ s v & ) < > | ] | n ( ? : a m e | ( ? : c o m p r e s s | s ( ? : e t | h a r e ) ) [ s v & ) < > | ] | e x p a n d | i q | l ( ? : i n k [ s v & ) < > | ] | z ( ? : 4
2025-01-07 18:00:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@pmFromFile windows-powershell-commands.data"
2025-01-07 18:00:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)(?:[nr;`{]|||?|&&?)[sv]*[sv\"'-(,@]*(?:[\"'.-9A-Z_a-z]+/|(?:[\"'x5c^]*[0-9A-Z_a-z][\"'x5c^]*:.*|[ \"'.-9A-Zx5c^-_a-z]*)x5c)?[\"^]*(?:(?:a[\"^]*(?:c|s[\"^]*n[\"^]*p)|e[\"^]*(?:b[\"^]*p|p[\"^]*(?:a[\"^]*l|c[\"^]*s[\"^]*v|s[\"^]*n)|[tx][\"^]*s[\"^]*n)|f[\"^]*(?:[cltw]|o[\"^]*r[\"^]*e[\"^]*a[\"^]*c[\"^]*h)|i[\"^]*(?:[cr][\"^]*m|e[\"^]*x|h[\"^]*y|i|p[\"^]*(?:a[\"^]*l|c[\"^]*s[\"^]*v|m[\"^]*o|s[\"^]*n)|s[\"^]*e|w[\"^]*(?:m[\"^]*i|r))|m[\"^]*(?:a[\"^]*n|[dipv]|o[\"^]*u[\"^]*n[\"^]*t)|o[\"^]*g[\"^]*v|p[\"^]*(?:o[\"^]*p|u[\"^]*s[\"^]*h)[\"^]*d|t[\"^]*r[\"^]*c[\"^]*m|w[\"^]*j[\"^]*b)[\"^]*[sv,.-/;-<>].*|c[\"^]*(?:(?:(?:d|h[\"^]*d[\"^]*i[\"^]*r|v[\"^]*p[\"^]*a)[\"^]*|p[\"^]*(?:[ip][\"^]*)?)[sv,.-/;-<>].*|l[\"^]*(?:(?:[cipv]|h[\"^]*y)[\"^]*[sv,.-/;-<>].*|s)|n[\"^]*s[\"^]*n)|d[\"^]*(?:(?:b[\"^]*p|e[\"^]*l|i[\"^]*(?:f[\"^]*f|r))[\"^]*[sv,.-/;-<>].*|n[\"^]*s[\"^]*n)|g[\"^]*(?:(?:(?:(?:a[\"^]*)?l|b[\"^]*p|d[\"^]*r|h[\"^]*y|(?:w[\"^]*m[\"^]*)?i|j[\"^]*b|[u-v])[\"^]*|c[\"^]*(?:[ims][\"^]*)?|m[\"^]*(?:o[\"^]*)?|s[\"^]*(?:n[\"^]*(?:p[\"^]*)?|v[\"^]*))[sv,.-/;-<>].*|e[\"^]*r[\"^]*r|p[\"^]*(?:(?:s[\"^]*)?[sv,.-/;-<>].*|v))|l[\"^]*s|n[\"^]*(?:(?:a[\"^]*l|d[\"^]*r|[iv]|m[\"^]*o|s[\"^]*n)[\"^]*[sv,.-/;-<>].*|p[\"^]*s[\"^]*s[\"^]*c)|r[\"^]*(?:(?:(?:(?:b[\"^]*)?p|e[\"^]*n|(?:w[\"^]*m[\"^]*)?i|j[\"^]*b|n[\"^]*[ip])[\"^]*|d[\"^]*(?:r[\"^]*)?|m[\"^]*(?:(?:d[\"^]*i[\"^]*r|o)[\"^]*)?|s[\"^]*n[\"^]*(?:p[\"^]*)?|v[\"^]*(?:p[\"^]*a[\"^]*)?)[sv,.-/;-<>].*|c[\"^]*(?:j[\"^]*b[\"^]*[sv,.-/;-<>].*|s[\"^]*n)|u[\"^]*j[\"^]*b)|s[\"^]*(?:(?:(?:a[\"^]*(?:j[\"^]*b|l|p[\"^]*s|s[\"^]*v)|b[\"^]*p|[civ]|w[\"^]*m[\"^]*i)[\"^]*|l[\"^]*(?:s[\"^]*)?|p[\"^]*(?:(?:j[\"^]*b|p[\"^]*s|s[\"^]*v)[\"^]*)?)[sv,.-/;-<>].*|h[\"^]*c[\"^]*m|u[\"^]*j[\"^]*b))(?:.[\"^]*[0-9A-Z_a-z]+)?b"
2025-01-27 00:26:20 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx $(?:((?:.*|(.*)))|{.*})|[<>](.*)|/[0-9A-Z_a-z]*[!?.+]"
2025-01-07 18:00:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx b(?:for(?:/[dflr].*)? %+[^ ]+ in(.*)[sv]?do|if(?:/i)?(?: not)?(?: (?:e(?:xist|rrorlevel)|defined|cmdextversion)b|[ (].*(?:b(?:g(?:eq|tr)|equ|neq|l(?:eq|ss))b|==)))"
2025-01-07 18:00:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)(?:^|=)[sv]*(?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*[sv]*[\"']*(?:[\"'-+--9?A-]_a-z|]+/)?[\"'x5c]*(?:7[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[arx])?|(?:b[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z|x)[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z|[ckz][\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?s[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?h|d[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?f|e[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:n[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?v|s[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?h)|f[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[dg]|g[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:c[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?c|p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?g)|(?:h[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?u|u[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d)[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p|i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?r[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?b|l[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:s|z(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?4)?)|p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:h[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p|w[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d|x[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z)|r[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?c(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p)?|s[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:c[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p|e[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d|(?:s[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?)?h|v[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?n)|w[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?3[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m)[sv&)<>|]"
2025-01-07 18:00:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)(?:^|=)[sv]*(?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*[sv]*[\"']*(?:[\"'-+--9?A-]_a-z|]+/)?[\"'x5c]*(?:a(?:ddgroup|xel)|b(?:ase(?:32|64|nc)|lkid|sd(?:cat|iff|tar)|u(?:iltin|nzip2|sybox)|yobu|z(?:c(?:at|mp)|diff|e(?:grep|xe)|f?grep|ip2(?:recover)?|less|more))|c(?:h(?:g(?:passwd|rp)|pass|sh)|lang++|oproc|ron)|d(?:iff[sv&)<>|]|mesg|oas)|e(?:2fsck|grep)|f(?:grep|iletest|tp(?:stats|who))|g(?:r(?:ep[sv&)<>|]|oupmod)|unzip|z(?:cat|exe|ip))|htop|l(?:ast(?:comm|log(?:in)?)|ess(?:echo|(?:fil|pip)e)|ftp(?:get)?|osetup|s(?:-F|b_release|cpu|mod|of|pci|usb)|wp-download|z(?:4c(?:at)?|c(?:at|mp)|diff|[e-f]?grep|less|m(?:a(?:dec|info)?|ore)))|m(?:a(?:ilq|ster.passwd)|k(?:fifo|nod|temp)|locate|ysql(?:admin|dump(?:slow)?|hotcopy|show))|n(?:c(?:.(?:openbsd|traditional)|at)|et(?:(?:c|st)at|kit-ftp|plan)|ohup|ping|stat)|onintr|p(?:dksh|erl5?|(?:ft|gre)p|hp(?:-cgi|[57])|igz|k(?:exec|ill)|(?:op|se)d|rint(?:env|f[sv&)<>|])|tar(?:diff|grep)?|wd.db|ython[2-3])|r(?:(?:bas|ealpat)h|m(?:dir[sv&)<>|]|user)|nano|sync)|s(?:diff|e(?:ndmail|t(?:env|sid))|ftp|(?:h.distri|pwd.d)b|ocat|td(?:err|in|out)|udo|ysctl)|t(?:ailf|c(?:p(?:ing|traceroute)|sh)|elnet|imeout[sv&)<>|]|raceroute6?)|u(?:n(?:ame|lz(?:4|ma)|(?:pig|x)z|rar|zstd)|ser(?:(?:ad|mo)d|del))|vi(?:gr|pw)|w(?:get|hoami)|x(?:args|z(?:c(?:at|mp)|d(?:ec|iff)|[e-f]?grep|less|more))|z(?:c(?:at|mp)|diff|[e-f]?grep|ip(?:c(?:loak|mp)|details|grep|info|(?:merg|not)e|split|tool)|less|more|run|std(?:(?:ca|m)t|grep|less)?))"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "!@rx [0-9]s*'s*[0-9]"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx !-d"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@pmFromFile unix-shell.data"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx ^(s*)s+{"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx ^(s*)s+{"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx ba[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?l[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?sb[sv]+[!-\"%',0-9@-Z_a-z]+=[^sv]"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@pmFromFile restricted-upload.data"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)(?:t[\"^]*i[\"^]*m[\"^]*e|[nr;`{]|||?|&&?)[sv]*[sv\"'-(,@]*(?:[\"'.-9A-Z_a-z]+/|(?:[\"'x5c^]*[0-9A-Z_a-z][\"'x5c^]*:.*|[ \"'.-9A-Zx5c^-_a-z]*)x5c)?[\"^]*(?:a[\"^]*(?:c[\"^]*c[\"^]*c[\"^]*h[\"^]*e[\"^]*c[\"^]*k[\"^]*c[\"^]*o[\"^]*n[\"^]*s[\"^]*o[\"^]*l[\"^]*e|d[\"^]*(?:p[\"^]*l[\"^]*u[\"^]*s|v[\"^]*p[\"^]*a[\"^]*c[\"^]*k)|(?:g[\"^]*e[\"^]*n[\"^]*t[\"^]*e[\"^]*x[\"^]*e[\"^]*c[\"^]*u[\"^]*t[\"^]*o|s[\"^]*p[\"^]*n[\"^]*e[\"^]*t[\"^]*_[\"^]*c[\"^]*o[\"^]*m[\"^]*p[\"^]*i[\"^]*l[\"^]*e)[\"^]*r|p[\"^]*p[\"^]*(?:i[\"^]*n[\"^]*s[\"^]*t[\"^]*a[\"^]*l[\"^]*l[\"^]*e[\"^]*r|v[\"^]*l[\"^]*p)|t[\"^]*(?:[sv,.-/;-<>].*|b[\"^]*r[\"^]*o[\"^]*k[\"^]*e[\"^]*r))|b[\"^]*(?:a[\"^]*s[\"^]*h|g[\"^]*i[\"^]*n[\"^]*f[\"^]*o|i[\"^]*t[\"^]*s[\"^]*a[\"^]*d[\"^]*m[\"^]*i[\"^]*n)|c[\"^]*(?:d[\"^]*b|e[\"^]*r[\"^]*t[\"^]*(?:o[\"^]*c|r[\"^]*e[\"^]*q|u[\"^]*t[\"^]*i[\"^]*l)|l[\"^]*_[\"^]*(?:i[\"^]*n[\"^]*v[\"^]*o[\"^]*c[\"^]*a[\"^]*t[\"^]*i[\"^]*o[\"^]*n|l[\"^]*o[\"^]*a[\"^]*d[\"^]*a[\"^]*s[\"^]*s[\"^]*e[\"^]*m[\"^]*b[\"^]*l[\"^]*y|m[\"^]*u[\"^]*t[\"^]*e[\"^]*x[\"^]*v[\"^]*e[\"^]*r[\"^]*i[\"^]*f[\"^]*i[\"^]*e[\"^]*r[\"^]*s)|m[\"^]*(?:d(?:[\"^]*(?:k[\"^]*e[\"^]*y|l[\"^]*3[\"^]*2))?|s[\"^]*t[\"^]*p)|o[\"^]*(?:m[\"^]*s[\"^]*v[\"^]*c[\"^]*s|n[\"^]*(?:f[\"^]*i[\"^]*g[\"^]*s[\"^]*e[\"^]*c[\"^]*u[\"^]*r[\"^]*i[\"^]*t[\"^]*y[\"^]*p[\"^]*o[\"^]*l[\"^]*i[\"^]*c[\"^]*y|h[\"^]*o[\"^]*s[\"^]*t|t[\"^]*r[\"^]*o[\"^]*l)|r[\"^]*e[\"^]*g[\"^]*e[\"^]*n)|r[\"^]*e[\"^]*a[\"^]*t[\"^]*e[\"^]*d[\"^]*u[\"^]*m[\"^]*p|s[\"^]*(?:c(?:[\"^]*r[\"^]*i[\"^]*p[\"^]*t)?|i)|u[\"^]*s[\"^]*t[\"^]*o[\"^]*m[\"^]*s[\"^]*h[\"^]*e[\"^]*l[\"^]*l[\"^]*h[\"^]*o[\"^]*s[\"^]*t)|d[\"^]*(?:a[\"^]*t[\"^]*a[\"^]*s[\"^]*v[\"^]*c[\"^]*u[\"^]*t[\"^]*i[\"^]*l|e[\"^]*(?:f[\"^]*a[\"^]*u[\"^]*l[\"^]*t[\"^]*p[\"^]*a[\"^]*c[\"^]*k|s[\"^]*k(?:[\"^]*t[\"^]*o[\"^]*p[\"^]*i[\"^]*m[\"^]*g[\"^]*d[\"^]*o[\"^]*w[\"^]*n[\"^]*l[\"^]*d[\"^]*r)?|v[\"^]*(?:i[\"^]*c[\"^]*e[\"^]*c[\"^]*r[\"^]*e[\"^]*d[\"^]*e[\"^]*n[\"^]*t[\"^]*i[\"^]*a[\"^]*l[\"^]*d[\"^]*e[\"^]*p[\"^]*l[\"^]*o[\"^]*y[\"^]*m[\"^]*e[\"^]*n[\"^]*t|t[\"^]*o[\"^]*o[\"^]*l[\"^]*s[\"^]*l[\"^]*a[\"^]*u[\"^]*n[\"^]*c[\"^]*h[\"^]*e[\"^]*r))|f[\"^]*s[\"^]*(?:h[\"^]*i[\"^]*m|v[\"^]*c)|i[\"^]*(?:a[\"^]*n[\"^]*t[\"^]*z|s[\"^]*k[\"^]*s[\"^]*h[\"^]*a[\"^]*d[\"^]*o[\"^]*w)|n[\"^]*(?:s[\"^]*c[\"^]*m[\"^]*d|x)|o[\"^]*t[\"^]*n[\"^]*e[\"^]*t|u[\"^]*m[\"^]*p[\"^]*6[\"^]*4|x[\"^]*c[\"^]*a[\"^]*p)|e[\"^]*(?:s[\"^]*e[\"^]*n[\"^]*t[\"^]*u[\"^]*t[\"^]*l|v[\"^]*e[\"^]*n[\"^]*t[\"^]*v[\"^]*w[\"^]*r|x[\"^]*(?:c[\"^]*e[\"^]*l|p[\"^]*(?:a[\"^]*n[\"^]*d|l[\"^]*o[\"^]*r[\"^]*e[\"^]*r)|t[\"^]*(?:e[\"^]*x[\"^]*p[\"^]*o[\"^]*r[\"^]*t|r[\"^]*a[\"^]*c[\"^]*3[\"^]*2)))|f[\"^]*(?:i[\"^]*n[\"^]*(?:d[\"^]*s[\"^]*t|g[\"^]*e)[\"^]*r|l[\"^]*t[\"^]*m[\"^]*c|o[\"^]*r[\"^]*f[\"^]*i[\"^]*l[\"^]*e[\"^]*s|s[\"^]*(?:i(?:[\"^]*a[\"^]*n[\"^]*y[\"^]*c[\"^]*p[\"^]*u)?|u[\"^]*t[\"^]*i[\"^]*l)|t[\"^]*p)|g[\"^]*(?:f[\"^]*x[\"^]*d[\"^]*o[\"^]*w[\"^]*n[\"^]*l[\"^]*o[\"^]*a[\"^]*d[\"^]*w[\"^]*r[\"^]*a[\"^]*p[\"^]*p[\"^]*e[\"^]*r|p[\"^]*s[\"^]*c[\"^]*r[\"^]*i[\"^]*p[\"^]*t)|h[\"^]*h|i[\"^]*(?:e[\"^]*(?:4[\"^]*u[\"^]*i[\"^]*n[\"^]*i[\"^]*t|a[\"^]*d[\"^]*v[\"^]*p[\"^]*a[\"^]*c[\"^]*k|e[\"^]*x[\"^]*e[\"^]*c|f[\"^]*r[\"^]*a[\"^]*m[\"^]*e)|l[\"^]*a[\"^]*s[\"^]*m|m[\"^]*e[\"^]*w[\"^]*d[\"^]*b[\"^]*l[\"^]*d|n[\"^]*(?:f[\"^]*d[\"^]*e[\"^]*f[\"^]*a[\"^]*u[\"^]*l[\"^]*t[\"^]*i[\"^]*n[\"^]*s[\"^]*t[\"^]*a[\"^]*l|s[\"^]*t[\"^]*a[\"^]*l[\"^]*l[\"^]*u[\"^]*t[\"^]*i)[\"^]*l)|j[\"^]*s[\"^]*c|l[\"^]*(?:a[\"^]*u[\"^]*n[\"^]*c[\"^]*h[\"^]*-[\"^]*v[\"^]*s[\"^]*d[\"^]*e[\"^]*v[\"^]*s[\"^]*h[\"^]*e[\"^]*l[\"^]*l|d[\"^]*i[\"^]*f[\"^]*d[\"^]*e)|m[\"^]*(?:a[\"^]*(?:k[\"^]*e[\"^]*c[\"^]*a[\"^]*b|n[\"^]*a[\"^]*g[\"^]*e[\"^]*-[\"^]*b[\"^]*d[\"^]*e|v[\"^]*i[\"^]*n[\"^]*j[\"^]*e[\"^]*c[\"^]*t)|f[\"^]*t[\"^]*r[\"^]*a[\"^]*c[\"^]*e|i[\"^]*c[\"^]*r[\"^]*o[\"^]*s[\"^]*o[\"^]*f[\"^]*t|m[\"^]*c|p[\"^]*c[\"^]*m[\"^]*d[\"^]*r[\"^]*u[\"^]*n|s[\"^]*(?:(?:b[\"^]*u[\"^]*i[\"^]*l|o[\"^]*h[\"^]*t[\"^]*m[\"^]*e)[\"^]*d|c[\"^]*o[\"^]*n[\"^]*f[\"^]*i[\"^]*g|d[\"^]*(?:e[\"^]*p[\"^]*l[\"^]*o[\"^]*y|t)|h[\"^]*t[\"^]*(?:a|m[\"^]*l)|i[\"^]*e[\"^]*x[\" ^
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)(?:t[\"^]*i[\"^]*m[\"^]*e|[nr;`{]|||?|&&?)[sv]*[sv\"'-(,@]*(?:[\"'.-9A-Z_a-z]+/|(?:[\"'x5c^]*[0-9A-Z_a-z][\"'x5c^]*:.*|[ \"'.-9A-Zx5c^-_a-z]*)x5c)?[\"^]*(?:a[\"^]*(?:s[\"^]*s[\"^]*o[\"^]*c|t[\"^]*(?:m[\"^]*a[\"^]*d[\"^]*m|t[\"^]*r[\"^]*i[\"^]*b)|u[\"^]*(?:d[\"^]*i[\"^]*t[\"^]*p[\"^]*o[\"^]*l|t[\"^]*o[\"^]*(?:c[\"^]*(?:h[\"^]*k|o[\"^]*n[\"^]*v)|(?:f[\"^]*m|m[\"^]*o[\"^]*u[\"^]*n)[\"^]*t)))|b[\"^]*(?:c[\"^]*d[\"^]*(?:b[\"^]*o[\"^]*o|e[\"^]*d[\"^]*i)[\"^]*t|(?:d[\"^]*e[\"^]*h[\"^]*d|o[\"^]*o[\"^]*t)[\"^]*c[\"^]*f[\"^]*g|i[\"^]*t[\"^]*s[\"^]*a[\"^]*d[\"^]*m[\"^]*i[\"^]*n)|c[\"^]*(?:a[\"^]*c[\"^]*l[\"^]*s|e[\"^]*r[\"^]*t[\"^]*(?:r[\"^]*e[\"^]*q|u[\"^]*t[\"^]*i[\"^]*l)|h[\"^]*(?:c[\"^]*p|d[\"^]*i[\"^]*r|g[\"^]*(?:l[\"^]*o[\"^]*g[\"^]*o[\"^]*n|p[\"^]*o[\"^]*r[\"^]*t|u[\"^]*s[\"^]*r)|k[\"^]*(?:d[\"^]*s[\"^]*k|n[\"^]*t[\"^]*f[\"^]*s))|l[\"^]*e[\"^]*a[\"^]*n[\"^]*m[\"^]*g[\"^]*r|m[\"^]*(?:d(?:[\"^]*k[\"^]*e[\"^]*y)?|s[\"^]*t[\"^]*p)|s[\"^]*c[\"^]*r[\"^]*i[\"^]*p[\"^]*t)|d[\"^]*(?:c[\"^]*(?:d[\"^]*i[\"^]*a[\"^]*g|g[\"^]*p[\"^]*o[\"^]*f[\"^]*i[\"^]*x)|e[\"^]*(?:f[\"^]*r[\"^]*a[\"^]*g|l)|f[\"^]*s[\"^]*(?:d[\"^]*i[\"^]*a|r[\"^]*m[\"^]*i)[\"^]*g|i[\"^]*(?:a[\"^]*n[\"^]*t[\"^]*z|r|s[\"^]*(?:k[\"^]*(?:c[\"^]*o[\"^]*(?:m[\"^]*p|p[\"^]*y)|p[\"^]*(?:a[\"^]*r[\"^]*t|e[\"^]*r[\"^]*f)|r[\"^]*a[\"^]*i[\"^]*d|s[\"^]*h[\"^]*a[\"^]*d[\"^]*o[\"^]*w)|p[\"^]*d[\"^]*i[\"^]*a[\"^]*g))|n[\"^]*s[\"^]*c[\"^]*m[\"^]*d|(?:o[\"^]*s[\"^]*k[\"^]*e|r[\"^]*i[\"^]*v[\"^]*e[\"^]*r[\"^]*q[\"^]*u[\"^]*e[\"^]*r)[\"^]*y)|e[\"^]*(?:n[\"^]*d[\"^]*l[\"^]*o[\"^]*c[\"^]*a[\"^]*l|v[\"^]*e[\"^]*n[\"^]*t[\"^]*c[\"^]*r[\"^]*e[\"^]*a[\"^]*t[\"^]*e)|E[\"^]*v[\"^]*n[\"^]*t[\"^]*c[\"^]*m[\"^]*d|f[\"^]*(?:c|i[\"^]*(?:l[\"^]*e[\"^]*s[\"^]*y[\"^]*s[\"^]*t[\"^]*e[\"^]*m[\"^]*s|n[\"^]*d[\"^]*s[\"^]*t[\"^]*r)|l[\"^]*a[\"^]*t[\"^]*t[\"^]*e[\"^]*m[\"^]*p|o[\"^]*r(?:[\"^]*f[\"^]*i[\"^]*l[\"^]*e[\"^]*s)?|r[\"^]*e[\"^]*e[\"^]*d[\"^]*i[\"^]*s[\"^]*k|s[\"^]*u[\"^]*t[\"^]*i[\"^]*l|(?:t[\"^]*y[\"^]*p|v[\"^]*e[\"^]*u[\"^]*p[\"^]*d[\"^]*a[\"^]*t)[\"^]*e)|g[\"^]*(?:e[\"^]*t[\"^]*(?:m[\"^]*a[\"^]*c|t[\"^]*y[\"^]*p[\"^]*e)|o[\"^]*t[\"^]*o|p[\"^]*(?:f[\"^]*i[\"^]*x[\"^]*u[\"^]*p|(?:r[\"^]*e[\"^]*s[\"^]*u[\"^]*l[\"^]*)?t|u[\"^]*p[\"^]*d[\"^]*a[\"^]*t[\"^]*e)|r[\"^]*a[\"^]*f[\"^]*t[\"^]*a[\"^]*b[\"^]*l)|h[\"^]*(?:e[\"^]*l[\"^]*p[\"^]*c[\"^]*t[\"^]*r|o[\"^]*s[\"^]*t[\"^]*n[\"^]*a[\"^]*m[\"^]*e)|i[\"^]*(?:c[\"^]*a[\"^]*c[\"^]*l[\"^]*s|f|p[\"^]*(?:c[\"^]*o[\"^]*n[\"^]*f[\"^]*i[\"^]*g|x[\"^]*r[\"^]*o[\"^]*u[\"^]*t[\"^]*e)|r[\"^]*f[\"^]*t[\"^]*p)|j[\"^]*e[\"^]*t[\"^]*p[\"^]*a[\"^]*c[\"^]*k|k[\"^]*(?:l[\"^]*i[\"^]*s[\"^]*t|s[\"^]*e[\"^]*t[\"^]*u[\"^]*p|t[\"^]*(?:m[\"^]*u[\"^]*t[\"^]*i[\"^]*l|p[\"^]*a[\"^]*s[\"^]*s))|l[\"^]*(?:o[\"^]*(?:d[\"^]*c[\"^]*t[\"^]*r|g[\"^]*(?:m[\"^]*a[\"^]*n|o[\"^]*f[\"^]*f))|p[\"^]*[q-r])|m[\"^]*(?:a[\"^]*(?:c[\"^]*f[\"^]*i[\"^]*l[\"^]*e|k[\"^]*e[\"^]*c[\"^]*a[\"^]*b|p[\"^]*a[\"^]*d[\"^]*m[\"^]*i[\"^]*n)|k[\"^]*(?:d[\"^]*i[\"^]*r|l[\"^]*i[\"^]*n[\"^]*k)|m[\"^]*c|o[\"^]*u[\"^]*n[\"^]*t[\"^]*v[\"^]*o[\"^]*l|q[\"^]*(?:b[\"^]*k[\"^]*u[\"^]*p|(?:t[\"^]*g[\"^]*)?s[\"^]*v[\"^]*c)|s[\"^]*(?:d[\"^]*t|i[\"^]*(?:e[\"^]*x[\"^]*e[\"^]*c|n[\"^]*f[\"^]*o[\"^]*3[\"^]*2)|t[\"^]*s[\"^]*c))|n[\"^]*(?:b[\"^]*t[\"^]*s[\"^]*t[\"^]*a[\"^]*t|e[\"^]*t[\"^]*(?:c[\"^]*f[\"^]*g|d[\"^]*o[\"^]*m|s[\"^]*(?:h|t[\"^]*a[\"^]*t))|f[\"^]*s[\"^]*(?:a[\"^]*d[\"^]*m[\"^]*i[\"^]*n|s[\"^]*(?:h[\"^]*a[\"^]*r[\"^]*e|t[\"^]*a[\"^]*t))|l[\"^]*(?:b[\"^]*m[\"^]*g[\"^]*r|t[\"^]*e[\"^]*s[\"^]*t)|s[\"^]*l[\"^]*o[\"^]*o[\"^]*k[\"^]*u[\"^]*p|t[\"^]*(?:b[\"^]*a[\"^]*c[\"^]*k[\"^]*u[\"^]*p|c[\"^]*m[\"^]*d[\"^]*p[\"^]*r[\"^]*o[\"^]*m[\"^]*p[\"^]*t|f[\"^]*r[\"^]*s[\"^]*u[\"^]*t[\"^]*l))|o[\"^]*(?:f[\"^]*f[\"^]*l[\"^]*i[\"^]*n[\"^]*e|p[\"^]*e[\"^]*n[\"^]*f[\"^]*i[\"^]*l[\"^]*e[\"^]*s)|p[\"^]*(?:a[\"^]*(?:g[\"^]*e[\"^]*f[\"^]*i[\"^]*l[\"^]*e[\"^]*c[\"^]*o[\"^]*n[\"^]*f[\"^]*i|t[\"^]*h[\"^]*p[\"^]*i[\"^]*n)[\"^]*g|(?:b[\"^]*a[\"^]*d[\"^]*m[\"^]*i|k[\"^]*t[\"^]*m[\"^]*o)[\"^]*n|e[\"^]*(?:n[\"^]*t[\"^]*n[\"^]*t|r[\"^]*f[\"^]*m[\"^]*o[\"^]*n)|n[\"^]*p[\"^]*u[\"^]*(?:n[\"^]*a[\"^]*t[\"^]*t[\"^]*e[\"^]*n[\"^]*d|t[\" ^
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@lt 2"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@lt 2"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[nr;`{]|||?|&&?|$(?:((?|{)|[<>](|([sv]*))[sv]*(?:[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*[sv]*[\"']*(?:[\"'-+--9?A-]_a-z|]+/)?[\"'x5c]*.[sv].*b"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?:$(?:((?:(.*)|.*))|{.*})|[<>](.*)|[!?.+])"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx ['*?x5c`][^n/]+/|/[^/]+?['*?x5c`]|$[!#-$(*-0-9?-[_a-{]"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx /"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx s"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx ^[^.]+.[^;?]+[;?](.*(['*?x5c`][^n/]+/|/[^/]+?['*?x5c`]|$[!#-$(*-0-9?-[_a-{]))"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx /"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx s"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx ^[^.]*?(?:['*?x5c`][^n/]+/|/[^/]+?['*?x5c`]|$[!#-$(*-0-9?-[_a-{])"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx /"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx s"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i).|(?:[sv]*|t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[nr;`{]|||?|&&?|$(?:((?|{)|[<>](|([sv]*))[sv]*(?:[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*[sv]*[\"']*(?:[\"'-+--9?A-]_a-z|]+/)?[\"'x5c]*(?:7[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[arx])?|G[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?E[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?T|a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:b|(?:p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?)?t|r(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[jp])?|s(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?h)?|w[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[ks])|b[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?z|c[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:[8-9][\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?9|[au][\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?t|c|(?:m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?)?p|s[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?h)|d[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:[dfu]|i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[gr])|e[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:[bdx]|n[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?v|q[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?n|s(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?h)?)|f[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:[c-dgi]|m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?t|t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p)|g[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:[chr][\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?c|d[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?b|e[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m|i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?t|o|p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?g)|h[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:d|u[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p)|i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:[dp]|r[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?b)|j[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:j[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?s|q)|k[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?s[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?h|l[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:d(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d)?|[nps]|u[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?a|z(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?4)?)|m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?n|t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?r|v)|n[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:[cl]|e[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?t|(?:p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?)?m)|o[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d|p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:[at][\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?x|d[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?b|f|(?:k[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?)?g|h[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p|i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[cp]|r(?:[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?y)?|w[\" ' )
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)[-0-9_a-z]+(?:[\"'[-]]+|$+[!#*-0-9?-@x5c_a-{]+|``|[$<>]())[sv]*[-0-9_a-z]+"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "!@rx [0-9]s*'s*[0-9]"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx ;[sv]*.[sv]*[\"']?(?:a(?:rchive|uth)|b(?:a(?:ckup|il)|inary)|c(?:d|h(?:anges|eck)|lone|onnection)|d(?:atabases|b(?:config|info)|ump)|e(?:cho|qp|x(?:cel|it|p(?:ert|lain)))|f(?:ilectrl|ullschema)|he(?:aders|lp)|i(?:mpo(?:rt|ster)|ndexes|otrace)|l(?:i(?:mi|n)t|o(?:ad|g))|(?:mod|n(?:onc|ullvalu)|unmodul)e|o(?:nce|pen|utput)|p(?:arameter|r(?:int|o(?:gress|mpt)))|quit|re(?:ad|cover|store)|s(?:ave|c(?:anstats|hema)|e(?:lftest|parator|ssion)|h(?:a3sum|ell|ow)?|tats|ystem)|t(?:ables|estc(?:ase|trl)|ime(?:out|r)|race)|vfs(?:info|list|name)|width)"
2025-02-06 00:25:50 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx rn(?s:.)*?b(?:(?i:E)(?:HLO [--.A-Za-zx17fx212a]{1,255}|XPN .{1,64})|HELO [--.A-Za-zx17fx212a]{1,255}|MAIL FROM:<.{1,64}(?i:@).{1,255}(?i:>)|(?i:R)(?:CPT TO:(?:(?i:<).{1,64}(?i:@).{1,255}(?i:>)|(?i: ))?(?i:<).{1,64}(?i:>)|SETb)|VRFY .{1,64}(?: <.{1,64}(?i:@).{1,255}(?i:>)|(?i:@).{1,255})|AUTH [-0-9A-Z_a-zx17fx212a]{1,20}(?i: )(?:(?:[+/-9A-Z_a-zx17fx212a]{4})*(?:[+/-9A-Z_a-zx17fx212a]{2}(?i:=)|[+/-9A-Z_a-zx17fx212a]{3}))?(?i:=)|STARTTLSb|NOOPb(?:(?i: ).{1,255})?)"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?is)rn[0-9A-Z_a-z]{1,50}b (?:A(?:PPEND (?:[\"-#%-&*--9A-Zx5c_a-z]+)?(?: ([ x5ca-z]+))?(?: \"?[0-9]{1,2}-[0-9A-Z_a-z]{3}-[0-9]{4} [0-9]{2}:[0-9]{2}:[0-9]{2} [+-][0-9]{4}\"?)? {[0-9]{1,20}+?}|UTHENTICATE [-0-9_a-z]{1,20}rn)|L(?:SUB (?:[\"-#*.-9A-Z_a-z~]+)? (?:[\"%-&*.-9A-Zx5c_a-z]+)?|ISTRIGHTS (?:[\"%-&*--9A-Zx5c_a-z]+)?)|S(?:TATUS (?:[\"%-&*--9A-Zx5c_a-z]+)? ((?:U(?:NSEEN|IDNEXT)|MESSAGES|UIDVALIDITY|RECENT| )+)|ETACL (?:[\"%-&*--9A-Zx5c_a-z]+)? [+-][ac-eik-lpr-tw-x]+?)|UID (?:COPY|FETCH|STORE) (?:[*,0-:]+)?|(?:(?:DELETE|GET)ACL|MYRIGHTS) (?:[\"%-&*--9A-Zx5c_a-z]+)?)"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?is)rn.*?b(?:(?:LIST|TOP [0-9]+)(?: [0-9]+)?|U(?:SER .+?|IDL(?: [0-9]+)?)|PASS .+?|(?:RETR|DELE) [0-9]+?|A(?:POP [0-9A-Z_a-z]+ [0-9a-f]{32}|UTH [-0-9A-Z_]{1,20} (?:(?:[+/-9A-Z_a-z]{4})*(?:[+/-9A-Z_a-z]{2}=|[+/-9A-Z_a-z]{3}))?=))"
2025-01-31 00:25:27 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)(?:(?:^|=)[sv]*(?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*|(?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[nr;`{]|||?|&&?|$(?:((?|{)|[<>](|([sv]*))[sv]*(?:[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*)[sv]*[\"']*(?:[\"'-+--9?A-]_a-z|]+/)?[\" ' x 5 c ] * ( ? : 7 z [ a r x ] ? | ( ? : ( ? : G E | P O S ) T | H E A D ) [ s v & ) < > | ] | a ( ? : ( ? : b | w [ k s ] | l ( ? : i a s | p i n e ) ) [ s v & ) < > | ] | p t ( ? : [ s v & ) < > | ] | - g e t ) | r ( ? : [ s v & ) < > j | ] | ( ? : p | c h ) [ s v & ) < > | ] | i a 2 c ) | s ( ? : h ? [ s v & ) < > | ] | c i i ( ? : - x f r | 85 ) | p e l l ) | t ( ? : [ s v & ) < > | ] | o b m ) | d d ( ? : g r o u p | u s e r ) | g e t t y | n s i b l e - p l a y b o o k | x e l ) | b ( ? : z ( ? : z [ s v & ) < > | ] | c ( ? : a t | m p ) | d i f f | e ( ? : g r e p | x e ) | f ? g r e p | i p 2 ( ? : r e c o v e r ) ? | l e s s | m o r e ) | a ( ? : s ( ? : e ( ? : 32 | 64 | n ( ? : a m e [ s v & ) < > | ] | c ) ) | h [ s v & ) < > | ] ) | t c h [ s v & ) < > | ] ) | l k i d | p f t r a c e | r ( ? : e a k s w | i d g e [ s v & ) < > | ] ) | s d ( ? : c a t | i f f | t a r ) | u ( ? : i l t i n | n ( ? : d l e r [ s v & ) < > | ] | z i p 2 ) | s ( ? : c t l | y b o x ) ) | y ( ? : e b u g | o b u ) ) | c ( ? : [ 8 -9 ] 9 | ( ? : a ( ? : t | n c e l | p s h ) | c ) [ s v & ) < > | ] | m p | p ( ? : [ s v & ) < > | ] | a n | i o | u l i m i t ) | s ( ? : h | p l i t | v t o o l ) | u ( ? : ( ? : t | r l ) [ s v & ) < > | ] | p s f i l t e r ) | e r t b o t | h ( ? : a t t r | ( ? : d i r | r o o t ) [ s v & ) < > | ] | e c k _ ( ? : b y _ s s h | c u p s | l o g | m e m o r y | r a i d | s ( ? : s l _ c e r t | t a t u s f i l e ) ) | ( ? : f l a g | p a s ) s | g ( ? : p a s s w d | r p ) | m o d | o ( ? : o m | w n ) | s h ) | l a n g ( ? : [ s v & ) < > | ] | + + ) | o ( ? : ( ? : b | p r o ) c | l u m n [ s v & ) < > | ] | m ( ? : m ( ? : a n d [ s v & ) < > | ] ) ? | p ( ? : o s e r | r e s s ) [ s v & ) < > | ] ) | w ( ? : s a y | t h i n k ) ) | r ( ? : a s h [ s v & ) < > | ] | o n ( ? : t a b ) ? ) ) | d ( ? : ( ? : [ d u ] | i ( ? : ( ? : a l o ) ? g | r | f f ) | a ( ? : s h | t e ) ) [ s v & ) < > | ] | f | h c l i e n t | m ( ? : e s g | i d e c o d e | s e t u p ) | o ( ? : a s | ( ? : c k e r | n e ) [ s v & ) < > | ] | s b o x ) | p k g | v i p s ) | e ( ? : ( ? : [ b d ] | c h o ) [ s v & ) < > | ] | n ( ? : v ( ? : - u p d a t e ) ? | d ( ? : i f | s w ) ) | q n | s ( ? : [ s v & ) < > h | ] | a c ) | x ( ? : ( ? : e c ) ? [ s v & ) < > | ] | i f t o o l | p ( ? : ( ? : a n d | ( ? : e c | o r ) t ) [ s v & ) < > | ] | r ) ) | 2 f s c k | ( ? : a s y _ i n s t a l | v a ) l | f a x | g r e p | m a c s ) | f ( ? : ( ? : c | e t c h | l o c k | u n c t i o n ) [ s v & ) < > | ] | d | g ( ? : r e p ) ? | i ( ? : ( ? : n ( ? : d | g e r ) | s h ) ? [ s v & ) < > | ] | l e ( ? : [ s v & ) < > | ] | t e s t ) ) | m t | t p ( ? : [ s v & ) < > | ] | s t a t s | w h o ) | a c t e r | o ( ? : l d [ s v & ) < > | ] | r e a c h ) | p i n g ) | g ( ? : c ( ? : c [ ^ s v ] | o r e ) | d b | e ( ? : ( ? : m | t f a c l ) [ s v & ) < > | ] | n i ( ? : e [ s v & ) < > | ] | s o i m a g e ) ) | h c i ? | i ( ? : ( ? : t | m p ) [ s v & ) < > | ] | n s h ) | ( ? : o | a w k ) [ s v & ) < > | ] | p g | r ( ? : c | e p [ s v & ) < > | ] | o u p ( ? : [ s v & ) < > | ] | m o d ) ) | t e s t e r | u n z i p | z ( ? : c a t | e x e | i p ) ) | h ( ? : ( ? : d | u p | a s h | i ( ? : g h l i g h t | s t o r y ) ) [ s v & ) < > | ] | e ( ? : a d [ s v & ) < > | ] | x d u m p ) | o s t ( ? : i d | n a m e ) | p i n g 3 | t ( ? : d i g e s t | o p | p a s s w d ) ) | i ( ? : d | p ( ? : 6 ? t a b l e s | c o n f i g ) ? | r b | c o n v | f ( ? : c o n f i g | t o p ) | n s t a l l [ s v & ) < > | ] | o n i c e | s p e l l ) | j ( ? : j s | q | a v a [ s v & ) < > | ] | e x e c | o ( ? : ( ? : b s | i n ) [ s v & ) < > | ] | u r n a l c t l ) | r u n s c r i p t ) | k ( ? : s ( ? : h | s h e l l ) | i l l ( ? : [ s v & ) < > | ] | a l l ) | n i f e [ s v & ) < > | ] ) | l ( ? : d ( ? : d ? [ s v & ) < > | ] | c o n f i g ) | ( ? : [ n p ] | i n k s | y n x ) [ s v & ) < > | ] | s ( ? : - F | b _ r e l e a s e | c p u | h w | m o d | o f | p c i | u s b ) ? | u a ( ? : [ s v & ) < > | ] | ( ? : l a ) ? t e x ) | z ( ? : [ s v & ) 4 < > | ] | 4 c ( ? : a t ) ? | c ( ? : a t | m p ) | d i f f | [ e - f ] ? g r e p | l e s s | m ( ? : a ( ? : d e c | i n f o ) ? | o r e ) ) | a ( ? : s t ( ? : [ s v & ) < > | ] | c o m m | l o g ( ? : i n ) ? ) | t e x [ s v & ) < > | ] ) | e s s ( ? : [ s v & ) < > | ] | e c h o | ( ? : f i l | p i p ) e ) | f t p ( ? : g e t ) ? | o ( ? : ( ? : c a ( ? : l | t e ) | o k ) [ s v & ) < > | ] | g ( ? : i n c t l | ( ? : n a m | s a v ) e ) | s e t u p ) | t r a c e | w p - ( ? : d ( ? : o w n l o a d | u m p ) | m i r r o r | r e q u e s t ) ) | m ( ? : a ( ? : ( ? : n | k e ) [ s v & ) < > | ] | i l ( ? : [ s v & ) < > q | ] | x [ s v & ) < > | ] ) | s t e r . p a s s w d | w k ) | t r | ( ? : v | u t t ) [ s v & ) < > | ] | k ( ? : d i r [ s v & ) < > | ] | f i f o | n o d | t e m p ) | l o c a t e | o ( ? : ( ? : r e | u n t ) [ s v & ) < > | ] | s q u i t t o ) | s g ( ? : a t t r i b | c ( ? : a t | o n v ) | f i l t e r | m e r g e | u n i q ) | y s q l ( ? : a d m i n | d u m p ( ? : s l o w ) ? | h o t c o p y | s h o w ) ? ) | n ( ? : c ( ? : [ s v & ) < > | ] | . ( ? : o p e n b s d | t r a d i t i o n a l ) | a t ) | e ( ? : t ( ? : [ s v & ) < > | ] | ( ? : c | s t ) a t | k i t - f t p | p l a n ) | o f e t c h ) | ( ? : ( ? : u l ) ? l | i c e ) [ s v & ) < > | ] | m ( ? : [ s v & ) < > | ] | a p ) | p ( ? : m [ s v & ) < > | ] | i n g ) | a ( ? : n o [ s v & ) < > | ] | s m | w k ) | o ( ? : d e [ s v & ) < > | ] | h u p ) | r o f f | s ( ? : e n t e r | l o o k u p | t a t ) ) | o ( ? : ( ? : d | c t a v e ) [ s v & ) < > | ] | n i n t r | p ( ? : e n ( ? : s s l | v ( ? : p n | t ) ) | k g ) ) | p ( ? : a ( ? : ( ? : x | r t e d | t c h ) [ s v & ) < > | ] | s ( ? : s w d | t e [ s v & ) < > | ] ) ) | d ( ? : b | f ( ? : l a ) ? t e x | k s h ) | f ( ? : [ s v & ) < > | ] | t p ) | g ( ? : r e p ) ? | h p ( ? : [ s v & ) 57 < > | ] | - c g i ) | i ( ? : ( ? : c o ? | n g ) [ s v & ) < > | ] | p [ ^ s v ] | d s t a t | g z ) | k ( ? : g ( ? : _ ? i n f o ) ? | e x e c | i l l ) | r ( ? : y ? [ s v & ) < > | ] | i n t ( ? : e n v | f [ s v & ) < > | ] ) ) | t ( ? : x | a r ( ? : d i f f | g r e p ) ? ) | w d ( ? : . d b ) ? | x z | e r ( ? : f | l ( ? : 5 | s h ) ? | m s [ s v & ) < > | ] ) | o p d | s ( ? : e d | f t p | q l ) | u ( ? : p p e t [ s v & ) < > | ] | s h d ) | y t h o n [ ^ s v ] ) | r ( ? : a ( ? : r [ s v & ) < > | ] | k ( ? : e [ s v & ) < > | ] | u ) ) | c ( ? : p [ s v & ) < > | ] ) ? | e ( ? : ( ? : d ( ? : c a r p e t ) ? | v | n a m e | p ( ? : e a t | l a c e ) ) [ s v & ) < > | ] | a ( ? : d e l f | l p a t h ) | s t i c ) | m ( ? : ( ? : d i r ) ? [ s v & ) < > | ] | u s e r ) | p m ( ? : [ s v & ) < > | ] | d b | ( ? : q u e r | v e r i f ) y ) |
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)(?:(?:^|=)[sv]*(?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*|(?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[nr;`{]|||?|&&?|$(?:((?|{)|[<>](|([sv]*))[sv]*(?:[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*)[sv]*[\"']*(?:[\"'-+--9?A-]_a-z|]+/)?[\" ' x 5 c ] * ( ? : 7 z [ a r x ] ? | ( ? : ( ? : G E | P O S ) T | H E A D ) [ s v & ) < > | ] | a ( ? : ( ? : b | w [ k s ] | l ( ? : i a s | p i n e ) ) [ s v & ) < > | ] | p t ( ? : [ s v & ) < > | ] | - g e t ) | r ( ? : [ s v & ) < > j | ] | ( ? : p | c h ) [ s v & ) < > | ] | i a 2 c ) | s ( ? : h ? [ s v & ) < > | ] | c i i ( ? : - x f r | 85 ) | p e l l ) | t ( ? : [ s v & ) < > | ] | o b m ) | d d ( ? : g r o u p | u s e r ) | g e t t y | n s i b l e - p l a y b o o k | x e l ) | b ( ? : z ( ? : z [ s v & ) < > | ] | c ( ? : a t | m p ) | d i f f | e ( ? : g r e p | x e ) | f ? g r e p | i p 2 ( ? : r e c o v e r ) ? | l e s s | m o r e ) | a ( ? : s ( ? : e ( ? : 32 | 64 | n ( ? : a m e [ s v & ) < > | ] | c ) ) | h [ s v & ) < > | ] ) | t c h [ s v & ) < > | ] ) | l k i d | p f t r a c e | r ( ? : e a k s w | i d g e [ s v & ) < > | ] ) | s d ( ? : c a t | i f f | t a r ) | u ( ? : i l t i n | n ( ? : d l e r [ s v & ) < > | ] | z i p 2 ) | s ( ? : c t l | y b o x ) ) | y ( ? : e b u g | o b u ) ) | c ( ? : [ 8 -9 ] 9 | ( ? : a ( ? : t | n c e l | p s h ) | c ) [ s v & ) < > | ] | m p | p ( ? : [ s v & ) < > | ] | i o | u l i m i t ) | s ( ? : h | p l i t | v t o o l ) | u ( ? : t [ s v & ) < > | ] | p s f i l t e r ) | e r t b o t | h ( ? : a t t r | ( ? : d i r | r o o t ) [ s v & ) < > | ] | e c k _ ( ? : b y _ s s h | c u p s | l o g | m e m o r y | r a i d | s ( ? : s l _ c e r t | t a t u s f i l e ) ) | ( ? : f l a g | p a s ) s | g ( ? : p a s s w d | r p ) | m o d | o ( ? : o m | w n ) | s h ) | l a n g ( ? : [ s v & ) < > | ] | + + ) | o ( ? : ( ? : b | p r o ) c | l u m n [ s v & ) < > | ] | m ( ? : m ( ? : a n d [ s v & ) < > | ] ) ? | p ( ? : o s e r | r e s s ) [ s v & ) < > | ] ) | w ( ? : s a y | t h i n k ) ) | r ( ? : a s h [ s v & ) < > | ] | o n ( ? : t a b ) ? ) ) | d ( ? : ( ? : [ d u ] | i ( ? : ( ? : a l o ) ? g | r | f f ) | a ( ? : s h | t e ) ) [ s v & ) < > | ] | f | h c l i e n t | m ( ? : e s g | i d e c o d e | s e t u p ) | o ( ? : a s | ( ? : c k e r | n e ) [ s v & ) < > | ] | s b o x ) | p k g | v i p s ) | e ( ? : ( ? : [ b d ] | c h o ) [ s v & ) < > | ] | n ( ? : v ( ? : - u p d a t e ) ? | d ( ? : i f | s w ) ) | q n | s ( ? : [ s v & ) < > h | ] | a c ) | x ( ? : ( ? : e c ) ? [ s v & ) < > | ] | i f t o o l | p ( ? : ( ? : a n d | ( ? : e c | o r ) t ) [ s v & ) < > | ] | r ) ) | 2 f s c k | ( ? : a s y _ i n s t a l | v a ) l | f a x | g r e p | m a c s ) | f ( ? : ( ? : c | e t c h | l o c k | u n c t i o n ) [ s v & ) < > | ] | d | g ( ? : r e p ) ? | i ( ? : ( ? : n ( ? : d | g e r ) | s h ) ? [ s v & ) < > | ] | l e ( ? : [ s v & ) < > | ] | t e s t ) ) | m t | t p ( ? : [ s v & ) < > | ] | s t a t s | w h o ) | a c t e r | o ( ? : l d [ s v & ) < > | ] | r e a c h ) | p i n g ) | g ( ? : c ( ? : c [ ^ s v ] | o r e ) | d b | e ( ? : ( ? : m | t f a c l ) [ s v & ) < > | ] | n i ( ? : e [ s v & ) < > | ] | s o i m a g e ) ) | h c i ? | i ( ? : ( ? : t | m p ) [ s v & ) < > | ] | n s h ) | ( ? : o | a w k ) [ s v & ) < > | ] | p g | r ( ? : c | e p [ s v & ) < > | ] | o u p ( ? : [ s v & ) < > | ] | m o d ) ) | t e s t e r | u n z i p | z ( ? : c a t | e x e | i p ) ) | h ( ? : ( ? : d | u p | a s h | i ( ? : g h l i g h t | s t o r y ) ) [ s v & ) < > | ] | e ( ? : a d [ s v & ) < > | ] | x d u m p ) | o s t ( ? : i d | n a m e ) | p i n g 3 | t ( ? : d i g e s t | o p | p a s s w d ) ) | i ( ? : d | p ( ? : 6 ? t a b l e s | c o n f i g ) ? | r b | c o n v | f ( ? : c o n f i g | t o p ) | n s t a l l [ s v & ) < > | ] | o n i c e | s p e l l ) | j ( ? : j s | q | a v a [ s v & ) < > | ] | e x e c | o ( ? : ( ? : b s | i n ) [ s v & ) < > | ] | u r n a l c t l ) | r u n s c r i p t ) | k ( ? : s ( ? : h | s h e l l ) | i l l ( ? : [ s v & ) < > | ] | a l l ) | n i f e [ s v & ) < > | ] ) | l ( ? : d ( ? : d ? [ s v & ) < > | ] | c o n f i g ) | ( ? : [ n p ] | y n x ) [ s v & ) < > | ] | s ( ? : - F | b _ r e l e a s e | c p u | h w | m o d | o f | p c i | u s b ) ? | u a ( ? : [ s v & ) < > | ] | ( ? : l a ) ? t e x ) | z ( ? : [ s v & ) 4 < > | ] | 4 c ( ? : a t ) ? | c ( ? : a t | m p ) | d i f f | [ e - f ] ? g r e p | l e s s | m ( ? : a ( ? : d e c | i n f o ) ? | o r e ) ) | a ( ? : s t ( ? : [ s v & ) < > | ] | c o m m | l o g ( ? : i n ) ? ) | t e x [ s v & ) < > | ] ) | e s s ( ? : [ s v & ) < > | ] | e c h o | ( ? : f i l | p i p ) e ) | f t p ( ? : g e t ) ? | o ( ? : ( ? : c a ( ? : l | t e ) | o k ) [ s v & ) < > | ] | g ( ? : i n c t l | ( ? : n a m | s a v ) e ) | s e t u p ) | t r a c e | w p - ( ? : d ( ? : o w n l o a d | u m p ) | m i r r o r | r e q u e s t ) ) | m ( ? : a ( ? : ( ? : n | k e ) [ s v & ) < > | ] | i l ( ? : [ s v & ) < > q | ] | x [ s v & ) < > | ] ) | s t e r . p a s s w d | w k ) | t r | ( ? : v | u t t ) [ s v & ) < > | ] | k ( ? : d i r [ s v & ) < > | ] | f i f o | n o d | t e m p ) | l o c a t e | o ( ? : ( ? : r e | u n t ) [ s v & ) < > | ] | s q u i t t o ) | s g ( ? : a t t r i b | c ( ? : a t | o n v ) | f i l t e r | m e r g e | u n i q ) | y s q l ( ? : a d m i n | d u m p ( ? : s l o w ) ? | h o t c o p y | s h o w ) ? ) | n ( ? : c ( ? : [ s v & ) < > | ] | . ( ? : o p e n b s d | t r a d i t i o n a l ) | a t ) | e ( ? : t ( ? : [ s v & ) < > | ] | ( ? : c | s t ) a t | k i t - f t p | p l a n ) | o f e t c h ) | ( ? : ( ? : u l ) ? l | i c e ) [ s v & ) < > | ] | m ( ? : [ s v & ) < > | ] | a p ) | p ( ? : m [ s v & ) < > | ] | i n g ) | a ( ? : n o [ s v & ) < > | ] | s m | w k ) | o ( ? : d e [ s v & ) < > | ] | h u p ) | r o f f | s ( ? : e n t e r | l o o k u p | t a t ) ) | o ( ? : ( ? : d | c t a v e ) [ s v & ) < > | ] | n i n t r | p ( ? : e n ( ? : s s l | v ( ? : p n | t ) ) | k g ) ) | p ( ? : a ( ? : ( ? : x | r t e d | t c h ) [ s v & ) < > | ] | s ( ? : s w d | t e [ s v & ) < > | ] ) ) | d ( ? : b | f ( ? : l a ) ? t e x | k s h ) | f ( ? : [ s v & ) < > | ] | t p ) | g ( ? : r e p ) ? | h p ( ? : [ s v & ) 57 < > | ] | - c g i ) | i ( ? : ( ? : c o ? | n g ) [ s v & ) < > | ] | p [ ^ s v ] | d s t a t | g z ) | k ( ? : g ( ? : _ ? i n f o ) ? | e x e c | i l l ) | r ( ? : y ? [ s v & ) < > | ] | i n t ( ? : e n v | f [ s v & ) < > | ] ) ) | t ( ? : x | a r ( ? : d i f f | g r e p ) ? ) | w d ( ? : . d b ) ? | x z | e r ( ? : f | l ( ? : 5 | s h ) ? | m s [ s v & ) < > | ] ) | o p d | s ( ? : e d | f t p | q l ) | u ( ? : p p e t [ s v & ) < > | ] | s h d ) | y t h o n [ 2 -3 ] ) | r ( ? : a ( ? : r [ s v & ) < > | ] | k ( ? : e [ s v & ) < > | ] | u ) ) | c ( ? : p [ s v & ) < > | ] ) ? | e ( ? : ( ? : d ( ? : c a r p e t ) ? | v | n a m e | p ( ? : e a t | l a c e ) ) [ s v & ) < > | ] | a ( ? : d e l f | l p a t h ) | s t i c ) | m ( ? : ( ? : d i r ) ? [ s v & ) < > | ] | u s e r ) | p m ( ? : [ s v & ) < > | ] | d b | ( ? : q u e r | v e r i f ) y ) | b a s h | l ( ? : o g i n | w
2025-01-07 18:00:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@pmFromFile unix-shell.data"
2025-01-07 18:00:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@lt 3"
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@lt 3"
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[nr;`{]|||?|&&?|$(?:((?|{)|[<>](|([sv]*))[sv]*(?:[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*[sv]*[\"']*(?:[\"'-+--9?A-]_a-z|]+/)?[\"'x5c]*(?:(?:(?:a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?u[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d|u[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?2[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?t)[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|v[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i)[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[sv&),<>|].*|d[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?n[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?f|p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?c[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?n[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[sv&),<>|].*|s)|w[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:h[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?o|[sv&),<>|].*))b"
2025-02-01 00:27:37 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : " @ r x ( ? i ) b ( ? : 7 z [ a r x ] ? | ( ? : ( ? : G E | P O S ) T | H E A D ) [ s v & ) < > | ] | a ( ? : ( ? : b | w [ k s ] | l ( ? : i a s | p i n e ) ) [ s v & ) < > | ] | p t ( ? : ( ? : i t u d e ) ? [ s v & ) < > | ] | - g e t ) | r ( ? : [ s v & ) < > j | ] | ( ? : p | c h ) [ s v & ) < > | ] | i a 2 c ) | s ( ? : h ? [ s v & ) < > | ] | c i i ( ? : - x f r | 85 ) | p e l l ) | t ( ? : [ s v & ) < > | ] | o b m ) | d d ( ? : g r o u p | u s e r ) | g e t t y | n s i b l e - p l a y b o o k | x e l ) | b ( ? : z ( ? : z [ s v & ) < > | ] | c ( ? : a t | m p ) | d i f f | e ( ? : g r e p | x e ) | f ? g r e p | i p 2 ( ? : r e c o v e r ) ? | l e s s | m o r e ) | a ( ? : s ( ? : e ( ? : 32 | 64 | n ( ? : a m e [ s v & ) < > | ] | c ) ) | h [ s v & ) < > | ] ) | t c h [ s v & ) < > | ] ) | l k i d | p f t r a c e | r ( ? : e a k s w | i d g e [ s v & ) < > | ] ) | s d ( ? : c a t | i f f | t a r ) | u ( ? : i l t i n | n ( ? : d l e r [ s v & ) < > | ] | z i p 2 ) | s ( ? : c t l | y b o x ) ) | y ( ? : e b u g | o b u ) ) | c ( ? : [ 8 -9 ] 9 | ( ? : a ( ? : t | n c e l | p s h ) | c ) [ s v & ) < > | ] | m p | p ( ? : [ s v & ) < > | ] | i o | u l i m i t ) | s ( ? : h | p l i t | v t o o l ) | u ( ? : t [ s v & ) < > | ] | p s f i l t e r ) | e r t b o t | h ( ? : a t t r | ( ? : d i r | r o o t ) [ s v & ) < > | ] | e c k _ ( ? : b y _ s s h | c u p s | l o g | m e m o r y | r a i d | s ( ? : s l _ c e r t | t a t u s f i l e ) ) | ( ? : f l a g | p a s ) s | g ( ? : p a s s w d | r p ) | m o d | o ( ? : o m | w n ) | s h ) | l a n g ( ? : [ s v & ) < > | ] | + + ) | o ( ? : ( ? : b | p r o ) c | l u m n [ s v & ) < > | ] | m ( ? : m ( ? : a n d [ s v & ) < > | ] ) ? | p ( ? : o s e r | r e s s ) [ s v & ) < > | ] ) | w ( ? : s a y | t h i n k ) ) | r ( ? : a s h [ s v & ) < > | ] | o n ( ? : t a b ) ? ) ) | d ( ? : ( ? : [ d u ] | i ( ? : ( ? : a l o ) ? g | r | f f ) | a ( ? : s h | t e ) ) [ s v & ) < > | ] | n ? f | h c l i e n t | m ( ? : e s g | i d e c o d e | s e t u p ) | o ( ? : a s | ( ? : c k e r | n e ) [ s v & ) < > | ] | s b o x ) | p k g | v i p s ) | e ( ? : ( ? : [ b d ] | c h o ) [ s v & ) < > | ] | n ( ? : v ( ? : - u p d a t e ) ? | d ( ? : i f | s w ) ) | q n | s ( ? : [ s v & ) < > h | ] | a c ) | x ( ? : ( ? : e c ) ? [ s v & ) < > | ] | i f t o o l | p ( ? : ( ? : a n d | ( ? : e c | o r ) t ) [ s v & ) < > | ] | r ) ) | 2 f s c k | ( ? : a s y _ i n s t a l | v a ) l | f a x | g r e p | m a c s ) | f ( ? : ( ? : c | e t c h | l o c k | u n c t i o n ) [ s v & ) < > | ] | d | g ( ? : r e p ) ? | i ( ? : ( ? : n ( ? : d | g e r ) | s h ) ? [ s v & ) < > | ] | l e ( ? : [ s v & ) < > | ] | t e s t ) ) | m t | t p ( ? : [ s v & ) < > | ] | s t a t s | w h o ) | a c t e r | o ( ? : l d [ s v & ) < > | ] | r e a c h ) | p i n g ) | g ( ? : c ( ? : c [ ^ s v ] | o r e ) | d b | e ( ? : ( ? : m | t f a c l ) [ s v & ) < > | ] | n i ( ? : e [ s v & ) < > | ] | s o i m a g e ) ) | h c i ? | i ( ? : ( ? : t | m p ) [ s v & ) < > | ] | n s h ) | ( ? : o | a w k ) [ s v & ) < > | ] | p g | r ( ? : c | e p [ s v & ) < > | ] | o u p ( ? : [ s v & ) < > | ] | m o d ) ) | t e s t e r | u n z i p | z ( ? : c a t | e x e | i p ) ) | h ( ? : ( ? : d | u p | a s h | i ( ? : g h l i g h t | s t o r y ) ) [ s v & ) < > | ] | e ( ? : a d [ s v & ) < > | ] | x d u m p ) | o s t ( ? : i d | n a m e ) | p i n g 3 | t ( ? : d i g e s t | o p | p a s s w d ) ) | i ( ? : d | p ( ? : 6 ? t a b l e s | c o n f i g ) ? | r b | c o n v | f ( ? : c o n f i g | t o p ) | n s t a l l [ s v & ) < > | ] | o n i c e | s p e l l ) | j ( ? : j s | q | a v a [ s v & ) < > | ] | e x e c | o ( ? : ( ? : b s | i n ) [ s v & ) < > | ] | u r n a l c t l ) | r u n s c r i p t ) | k ( ? : s ( ? : h | s h e l l ) | i l l ( ? : [ s v & ) < > | ] | a l l ) | n i f e [ s v & ) < > | ] ) | l ( ? : d ( ? : d ? [ s v & ) < > | ] | c o n f i g ) | ( ? : [ n p ] | y n x ) [ s v & ) < > | ] | s ( ? : - F | b _ r e l e a s e | c p u | h w | m o d | o f | p c i | u s b ) ? | u a ( ? : [ s v & ) < > | ] | ( ? : l a ) ? t e x ) | z ( ? : [ s v & ) 4 < > | ] | 4 c ( ? : a t ) ? | c ( ? : a t | m p ) | d i f f | [ e - f ] ? g r e p | l e s s | m ( ? : a ( ? : d e c | i n f o ) ? | o r e ) ) | a ( ? : s t ( ? : [ s v & ) < > | ] | c o m m | l o g ( ? : i n ) ? ) | t e x [ s v & ) < > | ] ) | e s s ( ? : [ s v & ) < > | ] | e c h o | ( ? : f i l | p i p ) e ) | f t p ( ? : g e t ) ? | o ( ? : ( ? : c a ( ? : l | t e ) | o k ) [ s v & ) < > | ] | g ( ? : i n c t l | ( ? : n a m | s a v ) e ) | s e t u p ) | t r a c e | w p - ( ? : d ( ? : o w n l o a d | u m p ) | m i r r o r | r e q u e s t ) ) | m ( ? : a ( ? : ( ? : n | k e ) [ s v & ) < > | ] | i l ( ? : [ s v & ) < > q | ] | x [ s v & ) < > | ] ) | s t e r . p a s s w d | w k ) | t r | ( ? : v | u t t ) [ s v & ) < > | ] | k ( ? : d i r [ s v & ) < > | ] | f i f o | n o d | t e m p ) | l o c a t e | o ( ? : ( ? : r e | u n t ) [ s v & ) < > | ] | s q u i t t o ) | s g ( ? : a t t r i b | c ( ? : a t | o n v ) | f i l t e r | m e r g e | u n i q ) | y s q l ( ? : a d m i n | d u m p ( ? : s l o w ) ? | h o t c o p y | s h o w ) ? ) | n ( ? : c ( ? : [ s v & ) < > | ] | . ( ? : o p e n b s d | t r a d i t i o n a l ) | a t ) | e ( ? : t ( ? : [ s v & ) < > | ] | ( ? : c | s t ) a t | k i t - f t p | p l a n ) | o f e t c h ) | ( ? : ( ? : u l ) ? l | i c e ) [ s v & ) < > | ] | m ( ? : [ s v & ) < > | ] | a p ) | p ( ? : m [ s v & ) < > | ] | i n g ) | a ( ? : n o [ s v & ) < > | ] | s m | w k ) | o ( ? : d e [ s v & ) < > | ] | h u p ) | r o f f | s ( ? : e n t e r | l o o k u p | t a t ) ) | o ( ? : ( ? : d | c t a v e ) [ s v & ) < > | ] | n i n t r | p ( ? : e n ( ? : s s l | v ( ? : p n | t ) ) | k g ) ) | p ( ? : a ( ? : ( ? : x | c m a n | r t e d | t c h ) [ s v & ) < > | ] | s ( ? : s w d | t e [ s v & ) < > | ] ) ) | d ( ? : b | f ( ? : l a ) ? t e x | k s h ) | f ( ? : [ s v & ) < > | ] | t p ) | g ( ? : r e p ) ? | h p ( ? : [ s v & ) 57 < > | ] | - c g i ) | i ( ? : ( ? : c o ? | n g ) [ s v & ) < > | ] | p [ ^ s v ] | d s t a t | g z ) | k ( ? : g ( ? : _ ? i n f o ) ? | e x e c | i l l ) | r ( ? : y ? [ s v & ) < > | ] | i n t ( ? : e n v | f [ s v & ) < > | ] ) ) | s ( ? : [ s v & ) < > | ] | e d | f t p | q l ) ? | t ( ? : x | a r ( ? : d i f f | g r e p ) ? ) | w d ( ? : . d b ) ? | x z | e r ( ? : f | l ( ? : 5 | s h ) ? | m s [ s v & ) < > | ] ) | o p d | u ( ? : p p e t [ s v & ) < > | ] | s h d ) | y t h o n [ 2 -3 ] ) | r ( ? : a ( ? : r [ s v & ) < > | ] | k ( ? : e [ s v & ) < > | ] | u ) ) | c ( ? : p [ s v & ) < > | ] ) ? | e ( ? : ( ? : d ( ? : c a r p e t ) ? | v | n a m e | p ( ? : e a t | l a c e ) ) [ s v & ) < > | ] | a ( ? : d e l f | l p a t h ) | s t i c ) | m ( ? : ( ? : d i r ) ? [ s v & ) < > | ] | u s e r ) | p m ( ? : [ s v & ) < > | ] | d b | ( ? : q u e r | v e r i f ) y ) | b a s h | l ( ? : o g i n | w r a p ) | n a n o | o u t e [ s v & ) < > | ] | s y n c | u ( ? : b y [ ^ s v ] | n - ( ? : m a i l c a p | p a r t s ) ) | v i ( ? : e w | m ) ) | s ( ? : c ( ? : p | h e d | r ( ? : e e n | i p t ) [ s v & ) < > | ] ) | e ( ? : ( ? : d | l f | r v i c e ) [ s v & ) < > | ] | t ( ? : a r c h | e n v | f a c l [ s v & ) < > | ] | s i d ) ? | n d m a i l ) | ( ? : g | a s h ) [ s v & ) < > | ] | h ( ? : ( ? : a d o w | e l l s ) ? [ s v & ) < > | ] | . d i s t r i b | u ( ? : f | t d o w n [ s v & ) < > | ] ) ) | s ( ? : [ s v & ) < > | ] | h ( ? : [ s v & ) < > | ] | - k e y ( ? : g e | s c a ) n | p a s s ) ) | u ( ? : [ s v & ) < > | ] | d o ) | v n | d i f f | f t p | l ( ? : e e p [ s v & ) < > | ] | s h ) | m b c l i e n t | o ( ? : c a t | e l i m | ( ? : r t | u r c e ) [ s v & ) < > | ] ) | p ( ? : l i t [ s v & ) < > | ] | w d . d b ) | q l i t e 3 | t ( ? : a r t - s t o p - d a e m o n | d ( ? : b u f | e r r | i n | o u t ) | r ( ? : a c e | i n g s [ s v & ) < > | ] ) ) | y s ( ? : c t l | t e m ( ? : c t l | d - r e s o l v e ) ) ) | t ( ? : a ( ? : c | r [ s v & ) < > | ] | i l [ s v & ) < > f | ] | s k ( ? : [ s v & ) < > | ] | s e t ) ) | b l | c ( ? : p ( ? : [ s v & ) < > | ] | d u m p | i n g | t r a c
2025-01-12 00:29:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?i)(?:(?:^|=)[sv]*(?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*|(?:t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|[nr;`{]|||?|&&?|$(?:((?|{)|[<>](|([sv]*))[sv]*(?:[${]|(?:[sv]*(|!)[sv]*|[0-9A-Z_a-z]+=(?:[^sv]*|$(?:.*|.*)|[<>].*|'.*'|\".*\")[sv]+)*)[sv]*[\"']*(?:[\"'-+--9?A-]_a-z|]+/)?[\"'x5c]*(?:(?:(?:a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?t[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?u[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d|u[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?2[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?d[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?t)[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?e|v[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?i)[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[sv&),<>|].*|d[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?n[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?f|p[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?c[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?m[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?a[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?n[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?[sv&),<>|].*|s)|w[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?(?:h[\"')[-x5c]*(?:(?:(?:|||&&)[sv]*)?$[!#(*-0-9?-@_a-{]*)?x5c?o|[sv&),<>|].*))"
2025-01-12 00:29:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx /(?:[?*]+[a-z/]+|[a-z/]+[?*]+)"
2025-01-12 00:29:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx rn(?s:.)*?b(?:DATA|QUIT|HELP(?: .{1,255})?)"
2025-01-12 00:29:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx (?is)rn[0-9A-Z_a-z]{1,50}b (?:C(?:(?:REATE|OPY [*,0-:]+) [\"-#%-&*--9A-Zx5c_a-z]+|APABILITY|HECK|LOSE)|DELETE [\"-#%-&*--.0-9A-Zx5c_a-z]+|EX(?:AMINE [\"-#%-&*--.0-9A-Zx5c_a-z]+|PUNGE)|FETCH [*,0-:]+|L(?:IST [\"-#*--9A-Zx5c_a-z~]+? [\"-#%-&*--9A-Zx5c_a-z]+|OG(?:IN [--.0-9@_a-z]{1,40} .*?|OUT))|RENAME [\"-#%-&*--9A-Zx5c_a-z]+? [\"-#%-&*--9A-Zx5c_a-z]+|S(?:E(?:LECT [\"-#%-&*--9A-Zx5c_a-z]+|ARCH(?: CHARSET [--.0-9A-Z_a-z]{1,40})? (?:(KEYWORD x5c)?(?:A(?:LL|NSWERED)|BCC|D(?:ELETED|RAFT)|(?:FLAGGE|OL)D|RECENT|SEEN|UN(?:(?:ANSWER|FLAGG)ED|D(?:ELETED|RAFT)|SEEN)|NEW)|(?:BODY|CC|FROM|HEADER .{1,100}|NOT|OR .{1,255}|T(?:EXT|O)) .{1,255}|LARGER [0-9]{1,20}|[*,0-:]+|(?:BEFORE|ON|S(?:ENT(?:(?:BEFOR|SINC)E|ON)|INCE)) \"?[0-9]{1,2}-[0-9A-Z_a-z]{3}-[0-9]{4}\"?|S(?:MALLER [0-9]{1,20}|UBJECT .{1,255})|U(?:ID [*,0-:]+?|NKEYWORD x5c(Seen|(?:Answer|Flagg)ed|D(?:eleted|raft)|Recent))))|T(?:ORE [*,0-:]+? [+-]?FLAGS(?:.SILENT)? (?:(x5c[a-z]{1,20}))?|ARTTLS)|UBSCRIBE [\"-#%-&*--9A-Zx5c_a-z]+)|UN(?:SUBSCRIBE [\"-#%-&*--9A-Zx5c_a-z]+|AUTHENTICATE)|NOOP)"
2025-01-12 00:29:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx rn(?s:.)*?b(?:(?:QUI|STA|RSE)(?i:T)|NOOP|CAPA)"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@rx !(?:d|!)"
2025-01-16 13:07:47 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@lt 4"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "RCE" ,
"pattern" : "@lt 4"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@lt 1"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@lt 1"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@pmFromFile java-code-leakages.data"
} ,
{
"category" : "JAVA" ,
"pattern" : "@pmFromFile java-errors.data"
} ,
{
"category" : "JAVA" ,
"pattern" : "@lt 2"
} ,
{
"category" : "JAVA" ,
"pattern" : "@lt 2"
} ,
{
"category" : "JAVA" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 3"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 3"
2025-01-16 00:26:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 4"
2025-01-16 00:26:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 4"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 1"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 1"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "!@pmFromFile sql-errors.data"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i:JET Database Engine|Access Database Engine|[Microsoft][ODBC Microsoft Access Driver])"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i:ORA-[0-9][0-9][0-9][0-9]|java.sql.SQLException|Oracle error|Oracle.*Driver|Warning.*oci_.*|Warning.*ora_.*)"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i:DB2 SQL error:|[IBM][CLI Driver][DB2/6000]|CLI Driver.*DB2|DB2 SQL error|db2_w+()"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i:[DM_QUERY_E_SYNTAX]|has occurred in the vicinity of:)"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i)Dynamic SQL Error"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i)Exception (?:condition )?d+. Transaction rollback."
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i)org.hsqldb.jdbc"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i:An illegal character has been found in the statement|com.informix.jdbc|Exception.*Informix)"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i:Warning.*ingres_|Ingres SQLSTATE|IngresW.*Driver)"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i:<b>Warning</b>: ibase_|Unexpected end of command in statement)"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i:SQL error.*POS[0-9]+.*|Warning.*maxdb.*)"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i)(?:System.Data.OleDb.OleDbException|[Microsoft][ODBC SQL Server Driver]|[Macromedia][SQLServer JDBC Driver]|[SqlException|System.Data.SqlClient.SqlException|Unclosed quotation mark after the character string|'80040e14'|mssql_query()|Microsoft OLE DB Provider for ODBC Drivers|Microsoft OLE DB Provider for SQL Server|Incorrect syntax near|Sintaxis incorrecta cerca de|Syntax error in string in query expression|Procedure or function .* expects parameter|Unclosed quotation mark before the character string|Syntax error .* in query expression|Data type mismatch in criteria expression.|ADODB.Field (0x800A0BCD)|the used select statements have different number of columns|OLE DB.*SQL Server|Warning.*mssql_.*|Driver.*SQL[ _-]*Server|SQL Server.*Driver|SQL Server.*[0-9a-fA-F]{8}|Exception.*WSystem.Data.SqlClient.|Conversion failed when converting the varchar value .*? to data type int.)"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i)(?:supplied argument is not a valid |SQL syntax.*)MySQL|Column count doesn't match(?: value count at row)?|mysql_fetch_array()|on MySQL result index|You have an error in your SQL syntax(?:;| near)|MyS(?:QL server version for the right syntax to use|qlClient.)|[MySQL][ODBC|(?:Table '[^']+' doesn't exis|valid MySQL resul)t|Warning.{1,10}mysql_(?:[(-)_a-z]{1,26})?|(?:ERROR [0-9]{4} ([0-9a-z]{5})|XPATH syntax error):"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i)P(?:ostgreSQL(?: query failed:|.{1,20}ERROR)|G::[a-z]*Error)|pg_(?:query|exec)() [:|Warning.{1,20}bpg_.*|valid PostgreSQL result|Npgsql.|Supplied argument is not a valid PostgreSQL .*? resource|(?:Unable to connect to PostgreSQL serv|invalid input syntax for integ)er"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i)(?:Warning.*sqlite_.*|Warning.*SQLite3::|SQLite/JDBCDriver|SQLite.Exception|System.Data.SQLite.SQLiteException)"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
"pattern" : "@rx (?i)(?:Sybase message:|Warning.{2,20}sybase|Sybase.*Server message.*)"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 2"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 2"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 3"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 3"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 4"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQL" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 4"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 1"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 1"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx java.lang.(?:runtime|processbuilder)"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?:runtime|processbuilder)"
2025-01-27 00:26:20 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?:unmarshaller|base64data|java.)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?:clonetransformer|forclosure|instantiatefactory|instantiatetransformer|invokertransformer|prototypeclonefactory|prototypeserializationfactory|whileclosure|getproperty|filewriter|xmldecoder)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?:runtime|processbuilder)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@pmFromFile java-classes.data"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx .*.(?:jsp|jspx).*$"
2025-01-16 00:26:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?i)(?:$|$?)(?:{|&l(?:brace|cub);?)(?:[^}]{0,15}(?:$|$?)(?:{|&l(?:brace|cub);?)|jndi|ctx)"
2024-12-21 01:02:34 +01:00
} ,
2025-01-16 13:07:47 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@lt 2"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@lt 2"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?i)(?:$|$?)(?:{|&l(?:brace|cub);?)(?:[^}]*(?:$|$?)(?:{|&l(?:brace|cub);?)|jndi|ctx)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx xacxedx00x05"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?:rO0ABQ|KztAAU|Cs7QAF)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?:clonetransformer|forclosure|instantiatefactory|instantiatetransformer|invokertransformer|prototypeclonefactory|prototypeserializationfactory|whileclosure|getproperty|filewriter|xmldecoder)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx javab.+(?:runtime|processbuilder)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?:class.module.classLoader.resources.context.parent.pipeline|springframework.context.support.FileSystemXmlApplicationContext)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 3"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 3"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?:cnVudGltZQ|HJ1bnRpbWU|BydW50aW1l|cHJvY2Vzc2J1aWxkZXI|HByb2Nlc3NidWlsZGVy|Bwcm9jZXNzYnVpbGRlcg|Y2xvbmV0cmFuc2Zvcm1lcg|GNsb25ldHJhbnNmb3JtZXI|BjbG9uZXRyYW5zZm9ybWVy|Zm9yY2xvc3VyZQ|GZvcmNsb3N1cmU|Bmb3JjbG9zdXJl|aW5zdGFudGlhdGVmYWN0b3J5|Gluc3RhbnRpYXRlZmFjdG9yeQ|BpbnN0YW50aWF0ZWZhY3Rvcnk|aW5zdGFudGlhdGV0cmFuc2Zvcm1lcg|Gluc3RhbnRpYXRldHJhbnNmb3JtZXI|BpbnN0YW50aWF0ZXRyYW5zZm9ybWVy|aW52b2tlcnRyYW5zZm9ybWVy|Gludm9rZXJ0cmFuc2Zvcm1lcg|BpbnZva2VydHJhbnNmb3JtZXI|cHJvdG90eXBlY2xvbmVmYWN0b3J5|HByb3RvdHlwZWNsb25lZmFjdG9yeQ|Bwcm90b3R5cGVjbG9uZWZhY3Rvcnk|cHJvdG90eXBlc2VyaWFsaXphdGlvbmZhY3Rvcnk|HByb3RvdHlwZXNlcmlhbGl6YXRpb25mYWN0b3J5|Bwcm90b3R5cGVzZXJpYWxpemF0aW9uZmFjdG9yeQ|d2hpbGVjbG9zdXJl|HdoaWxlY2xvc3VyZQ|B3aGlsZWNsb3N1cmU)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@lt 4"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@lt 4"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "JAVA" ,
"pattern" : "@rx (?i)(?:$|$?)(?:{|&l(?:brace|cub);?)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "!@eq 0"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "!@within |%{tx.allowed_request_content_type_charset}|"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx ^content-types*:s*(.*)$"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "!@rx ^(?:(?:*|[^!-\"(-),/:-?[-]{}]+)/(?:*|[^!-\"(-),/:-?[-]{}]+)|*)(?:[sv]*;[sv]*(?:charset[sv]*=[sv]*\"?(?:iso-8859-15?|utf-8|windows-1252)b\"?|(?:[^sv -\"(-),/:-?[-]c{}]|c(?:[^!-\"(-),/:-?[-]h{}]|h(?:[^!-\"(-),/:-?[-]a{}]|a(?:[^!-\"(-),/:-?[-]r{}]|r(?:[^!-\"(-),/:-?[-]s{}]|s(?:[^!-\"(-),/:-?[-]e{}]|e[^!-\"(-),/:-?[-]t{}]))))))[^!-\"(-),/:-?[-]{}]*[sv]*=[sv]*[^!(-),/:-?[-]{}]+);?)*(?:[sv]*,[sv]*(?:(?:*|[^!-\"(-),/:-?[-]{}]+)/(?:*|[^!-\"(-),/:-?[-]{}]+)|*)(?:[sv]*;[sv]*(?:charset[sv]*=[sv]*\"?(?:iso-8859-15?|utf-8|windows-1252)b\"?|(?:[^sv -\"(-),/:-?[-]c{}]|c(?:[^!-\"(-),/:-?[-]h{}]|h(?:[^!-\"(-),/:-?[-]a{}]|a(?:[^!-\"(-),/:-?[-]r{}]|r(?:[^!-\"(-),/:-?[-]s{}]|s(?:[^!-\"(-),/:-?[-]e{}]|e[^!-\"(-),/:-?[-]t{}]))))))[^!-\"(-),/:-?[-]{}]*[sv]*=[sv]*[^!(-),/:-?[-]{}]+);?)*)*$"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ATTACK" ,
"pattern" : "@rx content-transfer-encoding:(.*)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 1"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 1"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 2"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 2"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 3"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 3"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 4"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 4"
2025-02-07 00:25:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 1"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 1"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 2"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 2"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 3"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 3"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 4"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 4"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge %{tx.inbound_anomaly_score_threshold}"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@eq 1"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge %{tx.inbound_anomaly_score_threshold}"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 1"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 1"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 2"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 2"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 3"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 3"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 4"
2025-01-12 00:29:42 +00:00
} ,
2025-01-07 18:00:52 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 4"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@lt 1"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@lt 1"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@detectSQLi"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)b(?:d(?:atabas|b_nam)e[^0-9A-Z_a-z]*(|(?:information_schema|m(?:aster..sysdatabases|s(?:db|ys(?:ac(?:cess(?:objects|storage|xml)|es)|modules2?|(?:object|querie|relationship)s))|ysql.db)|northwind|pg_(?:catalog|toast)|tempdb)b|s(?:chema(?:_nameb|[^0-9A-Z_a-z]*()|(?:qlite_(?:temp_)?master|ys(?:aux|.database_name))b))"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)b(?:a(?:dd(?:dat|tim)e|es_(?:de|en)crypt|s(?:cii(?:str)?|in)|tan2?)|b(?:enchmark|i(?:n_to_num|t_(?:and|count|length|x?or)))|c(?:har(?:acter)?_length|iel(?:ing)?|o(?:alesce|ercibility|llation|(?:mpres)?s|n(?:cat(?:_ws)?|nection_id|v(?:ert(?:_tz)?)?)|t)|r32|ur(?:(?:dat|tim)e|rent_(?:date|setting|time(?:stamp)?|user)))|d(?:a(?:t(?:abase(?:_to_xml)?|e(?:_(?:add|format|sub)|diff))|y(?:name|of(?:month|week|year)))|count|e(?:code|grees|s_(?:de|en)crypt)|ump)|e(?:lt|n(?:c(?:ode|rypt)|ds_?with)|x(?:p(?:ort_set)?|tract(?:value)?))|f(?:i(?:el|n)d_in_set|ound_rows|rom_(?:base64|days|unixtime))|g(?:e(?:ometrycollection|t(?:_(?:format|lock)|pgusername))|(?:r(?:eates|oup_conca)|tid_subse)t)|hex(?:toraw)?|i(?:fnull|n(?:et6?_(?:aton|ntoa)|s(?:ert|tr)|terval)|s(?:_(?:(?:free|used)_lock|ipv(?:4(?:_(?:compat|mapped))?|6)|n(?:ot(?:_null)?|ull)|superuser)|null))|json(?:_(?:a(?:gg|rray(?:_(?:elements(?:_text)?|length))?)|build_(?:array|object)|e(?:ac|xtract_pat)h(?:_text)?|object(?:_(?:agg|keys))?|populate_record(?:set)?|strip_nulls|t(?:o_record(?:set)?|ypeof))|b(?:_(?:array(?:_(?:elements(?:_text)?|length))?|build_(?:array|object)|object(?:_(?:agg|keys))?|e(?:ac|xtract_pat)h(?:_text)?|insert|p(?:ath_(?:(?:exists|match)(?:_tz)?|query(?:_(?:(?:array|first)(?:_tz)?|tz))?)|opulate_record(?:set)?|retty)|s(?:et(?:_lax)?|trip_nulls)|t(?:o_record(?:set)?|ypeof)))?|path)?|l(?:ast_(?:day|inser_id)|case|e(?:as|f)t|i(?:kel(?:ihood|y)|nestring)|o(?:_(?:from_bytea|put)|ad_file|ca(?:ltimestamp|te)|g(?:10|2)|wer)|pad|trim)|m(?:a(?:ke(?:_set|date)|ster_pos_wait)|d5|i(?:crosecon)?d|onthname|ulti(?:linestring|po(?:int|lygon)))|n(?:ame_const|ot_in|ullif)|o(?:ct(?:et_length)?|(?:ld_passwo)?rd)|p(?:eriod_(?:add|diff)|g_(?:client_encoding|(?:databas|read_fil)e|l(?:argeobject|s_dir)|sleep|user)|o(?:(?:lyg|siti)on|w)|rocedure_analyse)|qu(?:arter|ery_to_xml|ote)|r(?:a(?:dians|nd|wtohex)|elease_lock|ow_(?:count|to_json)|pad|trim)|s(?:chema|e(?:c_to_time|ssion_user)|ha[1-2]?|in|oundex|pace|q(?:lite_(?:compileoption_(?:get|used)|source_id)|rt)|t(?:arts_?with|d(?:dev_(?:po|sam)p)?|r(?:_to_date|cmp))|ub(?:(?:dat|tim)e|str(?:ing(?:_index)?)?)|ys(?:date|tem_user))|t(?:ime(?:_(?:format|to_sec)|diff|stamp(?:add|diff)?)|o(?:_(?:base64|jsonb?)|n?char|(?:day|second)s)|r(?:im|uncate))|u(?:case|n(?:compress(?:ed_length)?|hex|i(?:str|x_timestamp)|likely)|(?:pdatexm|se_json_nul)l|tc_(?:date|time(?:stamp)?)|uid(?:_short)?)|var(?:_(?:po|sam)p|iance)|we(?:ek(?:day|ofyear)|ight_string)|xmltype|yearweek)[^0-9A-Z_a-z]*("
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i:sleep(s*?d*?s*?)|benchmark(.*?,.*?))"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)(?:select|;)[sv]+(?:benchmark|if|sleep)[sv]*?([sv]*?(?[sv]*?[0-9A-Z_a-z]+"
2025-01-30 00:24:54 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)[\"'`](?:[sv]*![sv]*[\"'0-9A-Z_-z]|;?[sv]*(?:having|select|unionb[sv]*(?:all|(?:distin|sele)ct))b[sv]*[^sv])|b(?:(?:(?:c(?:onnection_id|urrent_user)|database|schema|user)[sv]*?|select.*?[0-9A-Z_a-z]?user)(|exec(?:ute)?[sv]+master.|from[^0-9A-Z_a-z]+information_schema[^0-9A-Z_a-z]|into[sv+]+(?:dump|out)file[sv]*?[\"'`]|union(?:[sv]select[sv]@|[sv(0-9A-Z_a-z]*?select))|[sv]*?exec(?:ute)?.*?[^0-9A-Z_a-z]xp_cmdshell|[^0-9A-Z_a-z]iif[sv]*?("
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx ^(?i:-0000023456|4294967295|4294967296|2147483648|2147483647|0000012345|-2147483648|-2147483649|0000023456|2.2250738585072007e-308|2.2250738585072011e-308|1e309)$"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)[sv(-)]case[sv]+when.*?then|)[sv]*?like[sv]*?(|select.*?having[sv]*?[^sv]+[sv]*?[^sv0-9A-Z_a-z]|if[sv]?([0-9A-Z_a-z]+[sv]*?[<->~]"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)alter[sv]*?[0-9A-Z_a-z]+.*?char(?:acter)?[sv]+set[sv]+[0-9A-Z_a-z]+|[\"'`](?:;*?[sv]*?waitfor[sv]+(?:time|delay)[sv]+[\"'`]|;.*?:[sv]*?goto)"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i:merge.*?usings*?(|executes*?immediates*?[\"'`]|matchs*?[w(),+-]+s*?againsts*?()"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)union.*?select.*?from"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)select[sv]*?pg_sleep|waitfor[sv]*?delay[sv]?[\"'`]+[sv]?[0-9]|;[sv]*?shutdown[sv]*?(?:[#;{]|/*|--)"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)[?$(?:n(?:e|in?|o[rt])|e(?:q|xists|lemMatch)|l(?:te?|ike)|mod|a(?:ll|nd)|(?:s(?:iz|lic)|wher)e|t(?:ype|ext)|x?or|div|between|regex|jsonSchema)]?"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)create[sv]+(?:function|procedure)[sv]*?[0-9A-Z_a-z]+[sv]*?([sv]*?)[sv]*?-|d(?:eclare[^0-9A-Z_a-z]+[#@][sv]*?[0-9A-Z_a-z]+|iv[sv]*?([+-]*[sv.0-9]+,[+-]*[sv.0-9]+))|exec[sv]*?([sv]*?@|(?:lo_(?:impor|ge)t|procedure[sv]+analyse)[sv]*?(|;[sv]*?(?:declare|open)[sv]+[-0-9A-Z_a-z]+|::(?:b(?:igint|ool)|double[sv]+precision|int(?:eger)?|numeric|oid|real|(?:tex|smallin)t)"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)create[sv]+function[sv].+[sv]returns|;[sv]*?(?:alter|(?:(?:cre|trunc|upd)at|renam)e|d(?:e(?:lete|sc)|rop)|(?:inser|selec)t|load)b[sv]*?[([]?[0-9A-Z_a-z]{2,}"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)b(?:(?:alter|(?:(?:cre|trunc|upd)at|renam)e|de(?:lete|sc)|(?:inser|selec)t|load)[sv]+(?:char|group_concat|load_file)b[sv]*(?|end[sv]*?);)|[sv(]load_file[sv]*?(|[\"'`][sv]+regexp[^0-9A-Z_a-z]|[\"'0-9A-Z_-z][sv]+asb[sv]*[\"'0-9A-Z_-z]+[sv]*bfrom|^[^A-Z_a-z]+[sv]*?(?:(?:(?:(?:cre|trunc)at|renam)e|d(?:e(?:lete|sc)|rop)|(?:inser|selec)t|load)[sv]+[0-9A-Z_a-z]+|u(?:pdate[sv]+[0-9A-Z_a-z]+|nion[sv]*(?:all|(?:sele|distin)ct)b)|alter[sv]*(?:a(?:(?:ggregat|pplication[sv]*rol)e|s(?:sembl|ymmetric[sv]*ke)y|u(?:dit|thorization)|vailability[sv]*group)|b(?:roker[sv]*priority|ufferpool)|c(?:ertificate|luster|o(?:l(?:latio|um)|nversio)n|r(?:edential|yptographic[sv]*provider))|d(?:atabase|efault|i(?:mension|skgroup)|omain)|e(?:(?:ndpoi|ve)nt|xte(?:nsion|rnal))|f(?:lashback|oreign|u(?:lltext|nction))|hi(?:erarchy|stogram)|group|in(?:dex(?:type)?|memory|stance)|java|l(?:a(?:ngua|r)ge|ibrary|o(?:ckdown|g(?:file[sv]*group|in)))|m(?:a(?:s(?:k|ter[sv]*key)|terialized)|e(?:ssage[sv]*type|thod)|odule)|(?:nicknam|queu)e|o(?:perator|utline)|p(?:a(?:ckage|rtition)|ermission|ro(?:cedur|fil)e)|r(?:e(?:mot|sourc)e|o(?:l(?:e|lback)|ute))|s(?:chema|e(?:arch|curity|rv(?:er|ice)|quence|ssion)|y(?:mmetric[sv]*key|nonym)|togroup)|t(?:able(?:space)?|ext|hreshold|r(?:igger|usted)|ype)|us(?:age|er)|view|w(?:ork(?:load)?|rapper)|x(?:ml[sv]*schema|srobject))b)"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i:/*[!+](?:[ws=_-()]+)?*/)"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx ^(?:[^']*'|[^\"]*\"|[^`]*`)[sv]*;"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)1.e[(-),]"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx [\"'`][[{].*[]}][\"'`].*(::.*jsonb?)?.*(?:(?:@|->?)>|<@|?[&|]?|#>>?|[<>]|<-)|(?:(?:@|->?)>|<@|?[&|]?|#>>?|[<>]|<-)[\"'`][[{].*[]}][\"'`]|json_extract.*(.*)"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@lt 2"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@lt 2"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?:^s*[\"'`;]+|[\"'`]+s*$)"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)!=|&&||||>[=->]|<(?:<|=>?|>(?:[sv]+binary)?)|b(?:(?:xor|r(?:egexp|like)|i(?:snull|like)|notnull)b|collate(?:[^0-9A-Z_a-z]*?(?:U&)?[\"'`]|[^0-9A-Z_a-z]+(?:(?:binary|nocase|rtrim)b|[0-9A-Z_a-z]*?_))|(?:likel(?:ihood|y)|unlikely)[sv]*()|r(?:egexp|like)[sv]+binary|not[sv]+between[sv]+(?:0[sv]+and|(?:'[^']*'|\"[^\"]*\")[sv]+and[sv]+(?:'[^']*'|\"[^\"]*\"))|is[sv]+null|like[sv]+(?:null|[0-9A-Z_a-z]+[sv]+escapeb)|(?:^|[^0-9A-Z_a-z])in[sv+]*([sv\"0-9]+[^(-)]*)|[!<->]{1,2}[sv]*allb"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)[sv\"'-)`]*?b([0-9A-Z_a-z]+)b[sv\"'-)`]*?(?:=|<=>|(?:sounds[sv]+)?like|glob|r(?:like|egexp))[sv\"'-)`]*?b([0-9A-Z_a-z]+)b"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@streq %{TX.2}"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)[sv\"'-)`]*?b([0-9A-Z_a-z]+)b[sv\"'-)`]*?(?:![<->]|<[=->]?|>=?|^|is[sv]+not|not[sv]+(?:like|r(?:like|egexp)))[sv\"'-)`]*?b([0-9A-Z_a-z]+)b"
2025-02-04 00:25:09 +00:00
} ,
2025-02-03 00:26:12 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "!@streq %{TX.2}"
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)b(?:json(?:_[0-9A-Z_a-z]+)?|a(?:bs|(?:cos|sin)h?|tan[2h]?|vg)|c(?:eil(?:ing)?|h(?:a(?:nges|r(?:set)?)|r)|o(?:alesce|sh?|unt)|ast)|d(?:e(?:grees|fault)|a(?:te|y))|exp|f(?:loor(?:avg)?|ormat|ield)|g(?:lob|roup_concat)|h(?:ex|our)|i(?:f(?:null)?|if|n(?:str)?)|l(?:ast(?:_insert_rowid)?|ength|ike(?:l(?:ihood|y))?|n|o(?:ad_extension|g(?:10|2)?|wer(?:pi)?|cal)|trim)|m(?:ax|in(?:ute)?|o(?:d|nth))|n(?:ullif|ow)|p(?:i|ow(?:er)?|rintf|assword)|quote|r(?:a(?:dians|ndom(?:blob)?)|e(?:p(?:lace|eat)|verse)|ound|trim|ight)|s(?:i(?:gn|nh?)|oundex|q(?:lite_(?:compileoption_(?:get|used)|offset|source_id|version)|rt)|u(?:bstr(?:ing)?|m)|econd|leep)|t(?:anh?|otal(?:_changes)?|r(?:im|unc)|ypeof|ime)|u(?:n(?:icode|likely)|(?:pp|s)er)|zeroblob|bin|v(?:alues|ersion)|week|year)[^0-9A-Z_a-z]*("
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)(?:/*)+[\"'`]+[sv]?(?:--|[#{]|/*)?|[\"'`](?:[sv]*(?:(?:x?or|and|div|like|between)[sv-0-9A-Z_a-z]+[(-)+--<->][sv]*[\"'0-9`]|[!=|](?:[sv -!+-0-9=]+.*?[\"'-(`].*?|[sv -!0-9=]+.*?[0-9]+)$|(?:like|print)[^0-9A-Z_a-z]+[\"'-(0-9A-Z_-z]|;)|(?:[<>~]+|[sv]*[^sv0-9A-Z_a-z]?=[sv]*|[^0-9A-Z_a-z]*?[+=]+[^0-9A-Z_a-z]*?)[\"'`])|[0-9][\"'`][sv]+[\"'`][sv]+[0-9]|^admin[sv]*?[\"'`]|[sv\"'-(`][sv]*?glob[^0-9A-Z_a-z]+[\"'-(0-9A-Z_-z]|[sv]is[sv]*?0[^0-9A-Z_a-z]|where[sv][sv,-.0-9A-Z_a-z]+[sv]="
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i),.*?[\"')0-9`-f][\"'`](?:[\"'`].*?[\"'`]|(?:r?n)?z|[^\"'`]+)|[^0-9A-Z_a-z]select.+[^0-9A-Z_a-z]*?from|(?:alter|(?:(?:cre|trunc|upd)at|renam)e|d(?:e(?:lete|sc)|rop)|(?:inser|selec)t|load)[sv]*?([sv]*?space[sv]*?("
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)(?:&&||||and|between|div|like|n(?:and|ot)|(?:xx?)?or)[sv(]+[0-9A-Z_a-z]+[sv)]*?[!+=]+[sv0-9]*?[\"'-)=`]|[0-9](?:[sv]*?(?:and|between|div|like|x?or)[sv]*?[0-9]+[sv]*?[+-]|[sv]+group[sv]+by.+()|/[0-9A-Z_a-z]+;?[sv]+(?:and|between|div|having|like|x?or|select)[^0-9A-Z_a-z]|(?:[#;]|--)[sv]*?(?:alter|drop|(?:insert|update)[sv]*?[0-9A-Z_a-z]{2,})|@.+=[sv]*?([sv]*?select|[^0-9A-Z_a-z]SET[sv]*?@[0-9A-Z_a-z]+"
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)[\"'`][sv]*?(?:(?:and|n(?:and|ot)|(?:xx?)?or|div|like|between||||&&)[sv]+[sv0-9A-Z_a-z]+=[sv]*?[0-9A-Z_a-z]+[sv]*?having[sv]+|like[^0-9A-Z_a-z]*?[\"'0-9`])|[0-9A-Z_a-z][sv]+like[sv]+[\"'`]|like[sv]*?[\"'`]%|select[sv]+?[sv\"'-),-.0-9A-[]_-z]+from[sv]+"
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i))[sv]*?when[sv]*?[0-9]+[sv]*?then|[\"'`][sv]*?(?:[#{]|--)|/*![sv]?[0-9]+|b(?:(?:binary|cha?r)[sv]*?([sv]*?[0-9]|(?:and|n(?:and|ot)|(?:xx?)?or|div|like|between|r(?:egexp|like))[sv]+[0-9A-Z_a-z]+()|(?:|||&&)[sv]*?[0-9A-Z_a-z]+("
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)(?:([sv]*?select[sv]*?[0-9A-Z_a-z]+|coalesce|order[sv]+by[sv]+if[0-9A-Z_a-z]*?)[sv]*?(|*/from|+[sv]*?[0-9]+[sv]*?+[sv]*?@|[0-9A-Z_a-z][\"'`][sv]*?(?:(?:[+-=@|]+[sv]+?)+|[+-=@|]+)[(0-9]|@@[0-9A-Z_a-z]+[sv]*?[^sv0-9A-Z_a-z]|[^0-9A-Z_a-z]!+[\"'`][0-9A-Z_a-z]|[\"'`](?:;[sv]*?(?:if|while|begin)|[sv0-9]+=[sv]*?[0-9])|[sv(]+case[0-9]*?[^0-9A-Z_a-z].+[tw]hen[sv(]"
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)[\"'`][sv]*?b(?:x?or|div|like|between|and)b[sv]*?[\"'`]?[0-9]|x5cx(?:2[37]|3d)|^(?:.?[\"'`]$|[\"'x5c`]*?(?:[\"'0-9`]+|[^\"'`]+[\"'`])[sv]*?b(?:and|n(?:and|ot)|(?:xx?)?or|div|like|between||||&&)b[sv]*?[\"'0-9A-Z_-z][!&(-)+-.@])|[^sv0-9A-Z_a-z][0-9A-Z_a-z]+[sv]*?[-|][sv]*?[\"'`][sv]*?[0-9A-Z_a-z]|@(?:[0-9A-Z_a-z]+[sv]+(?:and|x?or|div|like|between)b[sv]*?[\"'0-9`]+|[-0-9A-Z_a-z]+[sv](?:and|x?or|div|like|between)b[sv]*?[^sv0-9A-Z_a-z])|[^sv0-:A-Z_a-z][sv]*?[0-9][^0-9A-Z_a-z]+[^sv0-9A-Z_a-z][sv]*?[\"'`].|[^0-9A-Z_a-z]information_schema|table_name[^0-9A-Z_a-z]"
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)in[sv]*?(+[sv]*?select|(?:(?:(?i:N)?AND|(?i:X)?(?i:X)?OR|DIV|LIKE|BETWEEN|NOT)[sv]+|(?:|||&&)[sv]*)[sv+0-9A-Z_a-z]+(?:regexp[sv]*?(|sounds[sv]+like[sv]*?[\"'`]|[0-9=]+x)|[\"'`](?:[sv]*?(?:[0-9][sv]*?(?:--|#)|is[sv]*?(?:[0-9].+[\"'`]?[0-9A-Z_a-z]|[.0-9]+[sv]*?[^0-9A-Z_a-z].*?[\"'`]))|[%-&<->^]+[0-9][sv]*?(?:=|x?or|div|like|between|and)|(?:[^0-9A-Z_a-z]+[+-0-9A-Z_a-z]+[sv]*?=[sv]*?[0-9][^0-9A-Z_a-z]+||?[-0-9A-Z_a-z]{3,}[^sv,.0-9A-Z_a-z]+)[\"'`]|[sv]*(?:(?:(?i:N)?AND|(?i:X)?(?i:X)?OR|DIV|LIKE|BETWEEN|NOT)[sv]+|(?:|||&&)[sv]*)(?:array[sv]*[|[0-9A-Z_a-z]+(?:[sv]*!?~|[sv]+(?:not[sv]+)?similar[sv]+to[sv]+)|(?:tru|fals)eb))|bexcept[sv]+(?:selectb|values[sv]*?()"
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i:^[Wd]+s*?(?:alter|union)b)"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)(?:alter|(?:(?:cre|trunc|upd)at|renam)e|de(?:lete|sc)|(?:inser|selec)t|load)[sv]+(?:char|group_concat|load_file)[sv]?(?|end[sv]*?);|[sv(]load_file[sv]*?(|[\"'`][sv]+regexp[^0-9A-Z_a-z]|[^A-Z_a-z][sv]+asb[sv]*[\"'0-9A-Z_-z]+[sv]*bfrom|^[^A-Z_a-z]+[sv]*?(?:create[sv]+[0-9A-Z_a-z]+|(?:d(?:e(?:lete|sc)|rop)|(?:inser|selec)t|load|(?:renam|truncat)e|u(?:pdate|nion[sv]*(?:all|(?:sele|distin)ct))|alter[sv]*(?:a(?:(?:ggregat|pplication[sv]*rol)e|s(?:sembl|ymmetric[sv]*ke)y|u(?:dit|thorization)|vailability[sv]*group)|b(?:roker[sv]*priority|ufferpool)|c(?:ertificate|luster|o(?:l(?:latio|um)|nversio)n|r(?:edential|yptographic[sv]*provider))|d(?:atabase|efault|i(?:mension|skgroup)|omain)|e(?:(?:ndpoi|ve)nt|xte(?:nsion|rnal))|f(?:lashback|oreign|u(?:lltext|nction))|hi(?:erarchy|stogram)|group|in(?:dex(?:type)?|memory|stance)|java|l(?:a(?:ngua|r)ge|ibrary|o(?:ckdown|g(?:file[sv]*group|in)))|m(?:a(?:s(?:k|ter[sv]*key)|terialized)|e(?:ssage[sv]*type|thod)|odule)|(?:nicknam|queu)e|o(?:perator|utline)|p(?:a(?:ckage|rtition)|ermission|ro(?:cedur|fil)e)|r(?:e(?:mot|sourc)e|o(?:l(?:e|lback)|ute))|s(?:chema|e(?:arch|curity|rv(?:er|ice)|quence|ssion)|y(?:mmetric[sv]*key|nonym)|togroup)|t(?:able(?:space)?|ext|hreshold|r(?:igger|usted)|ype)|us(?:age|er)|view|w(?:ork(?:load)?|rapper)|x(?:ml[sv]*schema|srobject)))b)"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)[\"'`](?:[sv]*?(?:(?:*.+(?:x?or|div|like|between|(?:an|i)d)[^0-9A-Z_a-z]*?[\"'`]|(?:x?or|div|like|between|and)[sv][^0-9]+[-0-9A-Z_a-z]+.*?)[0-9]|[^sv0-9?A-Z_a-z]+[sv]*?[^sv0-9A-Z_a-z]+[sv]*?[\"'`]|[^sv0-9A-Z_a-z]+[sv]*?[^A-Z_a-z].*?(?:#|--))|.*?*[sv]*?[0-9])|^[\"'`]|[%(-+-<>][-0-9A-Z_a-z]+[^sv0-9A-Z_a-z]+[\"'`][^,]"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)b(?:havingb(?:[sv]+(?:[0-9]{1,10}|'[^=]{1,10}')[sv]*?[<->]| ?(?:[0-9]{1,10} ?[<->]+|[\"'][^=]{1,10}[ \"'<-?[]+))|ex(?:ecute(?:(|[sv]{1,5}[$.0-9A-Z_a-z]{1,5}[sv]{0,3})|ists[sv]*?([sv]*?selectb)|(?:create[sv]+?table.{0,20}?|like[^0-9A-Z_a-z]*?char[^0-9A-Z_a-z]*?)()|select.*?case|from.*?limit|order[sv]by|exists[sv](?:[sv]select|s(?:elect[^sv](?:if(?:null)?[sv](|top|concat)|ystem[sv]()|bhavingb[sv]+[0-9]{1,10}|'[^=]{1,10}')"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)b(?:orb(?:[sv]?(?:[0-9]{1,10}|[\"'][^=]{1,10}[\"'])[sv]?[<->]+|[sv]+(?:[0-9]{1,10}|'[^=]{1,10}')(?:[sv]*?[<->])?)|xorb[sv]+(?:[0-9]{1,10}|'[^=]{1,10}')(?:[sv]*?[<->])?)|'[sv]+x?or[sv]+.{1,20}[!+-<->]"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)bandb(?:[sv]+(?:[0-9]{1,10}[sv]*?[<->]|'[^=]{1,10}')| ?(?:[0-9]{1,10}|[\"'][^=]{1,10}[\"']) ?[<->]+)"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)b(?:a(?:(?:b|co)s|dd(?:dat|tim)e|es_(?:de|en)crypt|s(?:in|cii(?:str)?)|tan2?|vg)|b(?:enchmark|i(?:n(?:_to_num)?|t_(?:and|count|length|x?or)))|c(?:ast|h(?:ar(?:(?:acter)?_length|set)?|r)|iel(?:ing)?|o(?:alesce|ercibility|(?:mpres)?s|n(?:cat(?:_ws)?|nection_id|v(?:ert(?:_tz)?)?)|(?:un)?t)|r32|ur(?:(?:dat|tim)e|rent_(?:date|time(?:stamp)?|user)))|d(?:a(?:t(?:abase|e(?:_(?:add|format|sub)|diff)?)|y(?:name|of(?:month|week|year))?)|count|e(?:code|(?:faul|s_(?:de|en)cryp)t|grees)|ump)|e(?:lt|nc(?:ode|rypt)|x(?:p(?:ort_set)?|tract(?:value)?))|f(?:i(?:eld(?:_in_set)?|nd_in_set)|loor|o(?:rmat|und_rows)|rom_(?:base64|days|unixtime))|g(?:et_(?:format|lock)|r(?:eates|oup_conca)t)|h(?:ex(?:toraw)?|our)|i(?:f(?:null)?|n(?:et6?_(?:aton|ntoa)|s(?:ert|tr)|terval)?|s(?:_(?:(?:free|used)_lock|ipv(?:4(?:_(?:compat|mapped))?|6)|n(?:ot(?:_null)?|ull))|null)?)|l(?:ast(?:_(?:day|insert_id))?|case|e(?:(?:as|f)t|ngth)|n|o(?:ad_file|ca(?:l(?:timestamp)?|te)|g(?:10|2)?|wer)|pad|trim)|m(?:a(?:ke(?:date|_set)|ster_pos_wait|x)|d5|i(?:(?:crosecon)?d|n(?:ute)?)|o(?:d|nth(?:name)?))|n(?:ame_const|o(?:t_in|w)|ullif)|o(?:ct(?:et_length)?|(?:ld_passwo)?rd)|p(?:assword|eriod_(?:add|diff)|g_sleep|i|o(?:sition|w(?:er)?)|rocedure_analyse)|qu(?:arter|ote)|r(?:a(?:dians|nd|wto(?:hex|nhex(?:toraw)?))|e(?:lease_lock|p(?:eat|lace)|verse)|ight|o(?:und|w_count)|pad|trim)|s(?:chema|e(?:c(?:ond|_to_time)|ssion_user)|ha[1-2]?|ig?n|leep|oundex|pace|qrt|t(?:d(?:dev(?:_(?:po|sam)p)?)?|r(?:cmp|_to_date))|u(?:b(?:(?:dat|tim)e|str(?:ing(?:_index)?)?)|m)|ys(?:date|tem_user))|t(?:an|ime(?:diff|_(?:format|to_sec)|stamp(?:add|diff)?)?|o_(?:base64|n?char|(?:day|second)s)|r(?:im|uncate))|u(?:case|n(?:compress(?:ed_length)?|hex|ix_timestamp)|p(?:datexml|per)|ser|tc_(?:date|time(?:stamp)?)|uid(?:_short)?)|v(?:a(?:lues|r(?:iance|_(?:po|sam)p))|ersion)|we(?:ek(?:day|ofyear)?|ight_string)|xmltype|year(?:week)?)[^0-9A-Z_a-z]*?("
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)autonomous_transaction|(?:current_use|n?varcha|tbcreato)r|db(?:a_users|ms_java)|open(?:owa_util|query|rowset)|s(?:p_(?:(?:addextendedpro|sqlexe)c|execute(?:sql)?|help|is_srvrolemember|makewebtask|oacreate|p(?:assword|repare)|replwritetovarbin)|ql_(?:longvarchar|variant))|utl_(?:file|http)|xp_(?:availablemedia|(?:cmdshel|servicecontro)l|dirtree|e(?:numdsn|xecresultset)|filelist|loginconfig|makecab|ntsec(?:_enumdomains)?|reg(?:addmultistring|delete(?:key|value)|enum(?:key|value)s|re(?:ad|movemultistring)|write)|terminate(?:_process)?)"
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)b(?:(?:d(?:bms_[0-9A-Z_a-z]+.|eleteb[^0-9A-Z_a-z]*?bfrom)|(?:groupb.*?bbyb.{1,100}?bhav|overlayb[^0-9A-Z_a-z]*?(.*?b[^0-9A-Z_a-z]*?plac)ing|in(?:nerb[^0-9A-Z_a-z]*?bjoin|sertb[^0-9A-Z_a-z]*?binto|tob[^0-9A-Z_a-z]*?b(?:dump|out)file)|loadb[^0-9A-Z_a-z]*?bdatab.*?binfile|s(?:electb.{1,100}?b(?:(?:.*?bdumpb.*|(?:count|length)b.{1,100}?)bfrom|(?:data_typ|fromb.{1,100}?bwher)e|instr|to(?:_(?:cha|numbe)r|pb.{1,100}?bfrom))|ys_context)|u(?:nionb.{1,100}?bselect|tl_inaddr))b|printb[^0-9A-Z_a-z]*?@@)|(?:collation[^0-9A-Z_a-z]*?(a|@@version|;[^0-9A-Z_a-z]*?b(?:drop|shutdown))b|'(?:dbo|msdasql|s(?:a|qloledb))'"
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx ((?:[~!@#$%^&*()-+={}[]|:;\"'\u00b4\u2019\u2018`<>][^~!@#$%^&*()-+={}[]|:;\"'\u00b4\u2019\u2018`<>]*?){12})"
2025-02-03 00:26:12 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx /*!?|*/|[';]--|--(?:[sv]|[^-]*?-)|[^&-]#.*?[sv]|;?x00"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "!@rx ^ey[-0-9A-Z_a-z]+.ey[-0-9A-Z_a-z]+.[-0-9A-Z_a-z]+$"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i:b0x[a-fd]{3,})"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?:`(?:(?:[ws=_-+{}()<@]){2,29}|(?:[A-Za-z0-9+/]{4})+(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?)`)"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)[\"'`][sv]*?(?:(?:is[sv]+not|not[sv]+(?:like|glob|(?:betwee|i)n|null|regexp|match)|mod|div|sounds[sv]+like)b|[%-&*-+-/<->^|])"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)^(?:[^']*?(?:'[^']*?'[^']*?)*?'|[^\"]*?(?:\"[^\"]*?\"[^\"]*?)*?\"|[^`]*?(?:`[^`]*?`[^`]*?)*?`)[sv]*([0-9A-Z_a-z]+)b"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx ^(?:and|or)$"
2025-01-29 00:25:14 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx ^.*?x5c['\"`](?:.*?['\"`])?s*(?:and|or)b"
2025-01-24 00:25:21 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@detectSQLi"
2025-01-24 00:25:21 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)b(?:a(?:dd(?:dat|tim)e|es_(?:de|en)crypt|s(?:cii(?:str)?|in)|tan2?)|b(?:enchmark|i(?:n_to_num|t_(?:and|count|length|x?or)))|c(?:har(?:acter)?_length|iel(?:ing)?|o(?:alesce|ercibility|llation|(?:mpres)?s|n(?:cat(?:_ws)?|nection_id|v(?:ert(?:_tz)?)?)|t)|r32|ur(?:(?:dat|tim)e|rent_(?:date|setting|time(?:stamp)?|user)))|d(?:a(?:t(?:abase(?:_to_xml)?|e(?:_(?:add|format|sub)|diff))|y(?:name|of(?:month|week|year)))|count|e(?:code|grees|s_(?:de|en)crypt)|ump)|e(?:lt|n(?:c(?:ode|rypt)|ds_?with)|x(?:p(?:ort_set)?|tract(?:value)?))|f(?:i(?:el|n)d_in_set|ound_rows|rom_(?:base64|days|unixtime))|g(?:e(?:ometrycollection|t(?:_(?:format|lock)|pgusername))|(?:r(?:eates|oup_conca)|tid_subse)t)|hex(?:toraw)?|i(?:fnull|n(?:et6?_(?:aton|ntoa)|s(?:ert|tr)|terval)|s(?:_(?:(?:free|used)_lock|ipv(?:4(?:_(?:compat|mapped))?|6)|n(?:ot(?:_null)?|ull)|superuser)|null))|json(?:_(?:a(?:gg|rray(?:_(?:elements(?:_text)?|length))?)|build_(?:array|object)|e(?:ac|xtract_pat)h(?:_text)?|object(?:_(?:agg|keys))?|populate_record(?:set)?|strip_nulls|t(?:o_record(?:set)?|ypeof))|b(?:_(?:array(?:_(?:elements(?:_text)?|length))?|build_(?:array|object)|object(?:_(?:agg|keys))?|e(?:ac|xtract_pat)h(?:_text)?|insert|p(?:ath_(?:(?:exists|match)(?:_tz)?|query(?:_(?:(?:array|first)(?:_tz)?|tz))?)|opulate_record(?:set)?|retty)|s(?:et(?:_lax)?|trip_nulls)|t(?:o_record(?:set)?|ypeof)))?|path)?|l(?:ast_(?:day|inser_id)|case|e(?:as|f)t|i(?:kel(?:ihood|y)|nestring)|o(?:_(?:from_bytea|put)|ad_file|ca(?:ltimestamp|te)|g(?:10|2)|wer)|pad|trim)|m(?:a(?:ke(?:_set|date)|ster_pos_wait)|d5|i(?:crosecon)?d|onthname|ulti(?:linestring|po(?:int|lygon)))|n(?:ame_const|ot_in|ullif)|o(?:ct(?:et_length)?|(?:ld_passwo)?rd)|p(?:eriod_(?:add|diff)|g_(?:client_encoding|(?:databas|read_fil)e|l(?:argeobject|s_dir)|sleep|user)|o(?:(?:lyg|siti)on|w)|rocedure_analyse)|qu(?:arter|ery_to_xml|ote)|r(?:a(?:dians|nd|wtohex)|elease_lock|ow_(?:count|to_json)|pad|trim)|s(?:chema|e(?:c_to_time|ssion_user)|ha[1-2]?|in|oundex|pace|q(?:lite_(?:compileoption_(?:get|used)|source_id)|rt)|t(?:arts_?with|d(?:dev_(?:po|sam)p)?|r(?:_to_date|cmp))|ub(?:(?:dat|tim)e|str(?:ing(?:_index)?)?)|ys(?:date|tem_user))|t(?:ime(?:_(?:format|to_sec)|diff|stamp(?:add|diff)?)|o(?:_(?:base64|jsonb?)|n?char|(?:day|second)s)|r(?:im|uncate))|u(?:case|n(?:compress(?:ed_length)?|hex|i(?:str|x_timestamp)|likely)|(?:pdatexm|se_json_nul)l|tc_(?:date|time(?:stamp)?)|uid(?:_short)?)|var(?:_(?:po|sam)p|iance)|we(?:ek(?:day|ofyear)|ight_string)|xmltype|yearweek)[^0-9A-Z_a-z]*("
2025-01-24 00:25:21 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)create[sv]+(?:function|procedure)[sv]*?[0-9A-Z_a-z]+[sv]*?([sv]*?)[sv]*?-|d(?:eclare[^0-9A-Z_a-z]+[#@][sv]*?[0-9A-Z_a-z]+|iv[sv]*?([+-]*[sv.0-9]+,[+-]*[sv.0-9]+))|exec[sv]*?([sv]*?@|(?:lo_(?:impor|ge)t|procedure[sv]+analyse)[sv]*?(|;[sv]*?(?:declare|open)[sv]+[-0-9A-Z_a-z]+|::(?:b(?:igint|ool)|double[sv]+precision|int(?:eger)?|numeric|oid|real|(?:tex|smallin)t)"
2025-01-24 00:25:21 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@lt 3"
2025-01-24 00:25:21 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@lt 3"
2025-01-24 00:25:21 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?i)W+d*?s*?bhavingbs*?[^s-]"
2025-01-24 00:25:21 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx [\"'`][sd]*?[^ws]W*?dW*?.*?[\"'`d]"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx ((?:[~!@#$%^&*()-+={}[]|:;\"'\u00b4\u2019\u2018`<>][^~!@#$%^&*()-+={}[]|:;\"'\u00b4\u2019\u2018`<>]*?){8})"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx ((?:[~!@#$%^&*()-+={}[]|:;\"'\u00b4\u2019\u2018`<>][^~!@#$%^&*()-+={}[]|:;\"'\u00b4\u2019\u2018`<>]*?){6})"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx W{4}"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx (?:'(?:(?:[ws=_-+{}()<@]){2,29}|(?:[A-Za-z0-9+/]{4})+(?:[A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?)')"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx ';"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@lt 4"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@lt 4"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx ((?:[~!@#$%^&*()-+={}[]|:;\"'\u00b4\u2019\u2018`<>][^~!@#$%^&*()-+={}[]|:;\"'\u00b4\u2019\u2018`<>]*?){3})"
2024-12-21 01:02:34 +01:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "SQLI" ,
"pattern" : "@rx ((?:[~!@#$%^&*()-+={}[]|:;\"'\u00b4\u2019\u2018`<>][^~!@#$%^&*()-+={}[]|:;\"'\u00b4\u2019\u2018`<>]*?){2})"
2025-01-07 00:27:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 1"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 1"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
"pattern" : "@rx (?:<(?:TITLE>Index of.*?<H|title>Index of.*?<h)1>Index of|>[To Parent Directory]</[Aa]><br>)"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
"pattern" : "@rx ^#!s?/"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 2"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 2"
2025-01-16 00:26:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
"pattern" : "@rx ^5d{2}$"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 3"
2025-01-16 00:26:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 3"
2025-01-16 00:26:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 4"
2025-01-16 00:26:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "LEAKAGES" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 4"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 1"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 1"
2025-01-25 00:24:31 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@within %{tx.allowed_methods}"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
2025-02-24 00:27:16 +00:00
"pattern" : "@lt 2"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 2"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 3"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 3"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 4"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 4"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 1"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 1"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx (?i)^(?:get /[^#?]*(?:?[^sv#]*)?(?:#[^sv]*)?|(?:connect (?:(?:[0-9]{1,3}.){3}[0-9]{1,3}.?(?::[0-9]+)?|[--9A-Z_a-z]+:[0-9]+)|options *|[a-z]{3,10}[sv]+(?:[0-9A-Z_a-z]{3,7}?://[--9A-Z_a-z]*(?::[0-9]+)?)?/[^#?]*(?:?[^sv#]*)?(?:#[^sv]*)?)[sv]+[.-9A-Z_a-z]+)$"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx (?i)^(?:&(?:(?:[acegiln-or-suz]acut|[aeiou]grav|[ain-o]tild)e|[c-elnr-tz]caron|(?:[cgk-lnr-t]cedi|[aeiouy]um)l|[aceg-josuwy]circ|[au]ring|a(?:mp|pos)|nbsp|oslash);|[^\"';=])*$"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^d+$"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^(?:GET|HEAD)$"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^0?$"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^(?:GET|HEAD)$"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@eq 0"
2025-01-25 00:24:31 +00:00
} ,
2025-01-17 00:25:08 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@within HTTP/2 HTTP/2.0 HTTP/3 HTTP/3.0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@streq POST"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@eq 0"
2025-02-05 00:25:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@eq 0"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx (d+)-(d+)"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt %{tx.1}"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx b(?:keep-alive|close),s?(?:keep-alive|close)b"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx x25"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@validateUrlEncoding"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^(?i)application/x-www-form-urlencoded"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx x25"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@validateUrlEncoding"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 1"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@validateUtf8Encoding"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx %u[fF]{2}[0-9a-fA-F]{2}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@validateByteRange 1-255"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 0"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^$"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^$"
2025-02-02 00:27:06 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^OPTIONS$"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@pm AppleWebKit Android Business Enterprise Entreprise"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^$"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^OPTIONS$"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 0"
2025-02-23 00:28:29 +00:00
} ,
2025-02-08 00:25:04 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^$"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^0$"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 0"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx (?:^([d.]+|[[da-f:]+]|[da-f:]+)(:[d]+)?$)"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 1"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@gt %{tx.max_num_args}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 1"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@gt %{tx.arg_name_length}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 1"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@gt %{tx.arg_length}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 1"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@gt %{tx.total_arg_length}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 1"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^(?i)multipart/form-data"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@gt %{tx.max_file_size}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 1"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@gt %{tx.combined_file_sizes}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^[w/.+*-]+(?:s?;s?(?:action|boundary|charset|component|start(?:-info)?|type|version)s?=s?['\"w.()+,/:=?<>@#*-]+)*$"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^[^;s]+"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@within %{tx.allowed_request_content_type}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx charsets*=s*[\"']?([^;\"'s]+)"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@within %{tx.allowed_request_content_type_charset}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx charset.*?charset"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@within %{tx.allowed_http_versions}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx .([^.]+)$"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@within %{tx.restricted_extensions}"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx .[^.~]+~(?:/.*|)$"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^.*$"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@within %{tx.restricted_headers_basic}"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@gt 50"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^(?:(?:*|[^!-\"(-),/:-?[-]{}]+)/(?:*|[^!-\"(-),/:-?[-]{}]+)|*)(?:[sv]*;[sv]*(?:charset[sv]*=[sv]*\"?(?:iso-8859-15?|utf-8|windows-1252)b\"?|(?:[^sv -\"(-),/:-?[-]c{}]|c(?:[^!-\"(-),/:-?[-]h{}]|h(?:[^!-\"(-),/:-?[-]a{}]|a(?:[^!-\"(-),/:-?[-]r{}]|r(?:[^!-\"(-),/:-?[-]s{}]|s(?:[^!-\"(-),/:-?[-]e{}]|e[^!-\"(-),/:-?[-]t{}]))))))[^!-\"(-),/:-?[-]{}]*[sv]*=[sv]*[^!(-),/:-?[-]{}]+);?)*(?:[sv]*,[sv]*(?:(?:*|[^!-\"(-),/:-?[-]{}]+)/(?:*|[^!-\"(-),/:-?[-]{}]+)|*)(?:[sv]*;[sv]*(?:charset[sv]*=[sv]*\"?(?:iso-8859-15?|utf-8|windows-1252)b\"?|(?:[^sv -\"(-),/:-?[-]c{}]|c(?:[^!-\"(-),/:-?[-]h{}]|h(?:[^!-\"(-),/:-?[-]a{}]|a(?:[^!-\"(-),/:-?[-]r{}]|r(?:[^!-\"(-),/:-?[-]s{}]|s(?:[^!-\"(-),/:-?[-]e{}]|e[^!-\"(-),/:-?[-]t{}]))))))[^!-\"(-),/:-?[-]{}]*[sv]*=[sv]*[^!(-),/:-?[-]{}]+);?)*)*$"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@streq JSON"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx (?i)x5cu[0-9a-f]{4}"
2025-01-17 00:25:08 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@contains #"
2025-01-17 00:25:08 +00:00
} ,
2025-01-28 00:25:35 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@gt 1"
2025-01-30 00:24:54 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 2"
2025-01-30 00:24:54 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 2"
2025-01-30 00:24:54 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^bytes=(?:(?:d+)?-(?:d+)?s*,?s*){6}"
2025-01-30 00:24:54 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@endsWith .pdf"
2025-01-30 00:24:54 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@endsWith .pdf"
2025-01-30 00:24:54 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^bytes=(?:(?:d+)?-(?:d+)?s*,?s*){63}"
2025-01-30 00:24:54 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx %[0-9a-fA-F]{2}"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@validateByteRange 9,10,13,32-126,128-255"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 0"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ['\";=]"
2025-02-04 00:25:09 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^0$"
2025-02-07 00:25:52 +00:00
} ,
2025-02-09 00:27:59 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 0"
2025-02-09 00:27:59 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^.*$"
2025-02-09 00:27:59 +00:00
} ,
2025-02-07 00:25:52 +00:00
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@within %{tx.restricted_headers_extended}"
2025-02-07 00:25:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 3"
2025-02-07 00:25:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 3"
2025-02-07 00:25:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@validateByteRange 32-36,38-126"
2025-02-07 00:25:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@eq 0"
2025-02-07 00:25:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^(?:OPTIONS|CONNECT)$"
2025-02-07 00:25:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@pm AppleWebKit Android"
2025-02-07 00:25:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@ge 1"
2025-02-07 00:25:52 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^(?i)up"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@gt 0"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^(?:(?:max-age=[0-9]+|min-fresh=[0-9]+|no-cache|no-store|no-transform|only-if-cached|max-stale(?:=[0-9]+)?)(?:s*,s*|$)){1,7}$"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx br|compress|deflate|(?:pack200-)?gzip|identity|*|^$|aes128gcm|exi|zstd|x-(?:compress|gzip)"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 4"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@lt 4"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@endsWith .pdf"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx ^bytes=(?:(?:d+)?-(?:d+)?s*,?s*){6}"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@validateByteRange 38,44-46,48-58,61,65-90,95,97-122"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@validateByteRange 32,34,38,42-59,61,65-90,95,97-122"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "!@rx ^(?:?[01])?$"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "ENFORCEMENT" ,
"pattern" : "@rx (?:^|[^x5c])x5c[cdeghijklmpqwxyz123456789]"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@lt 1"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@lt 1"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "!@validateByteRange 20, 45-47, 48-57, 65-90, 95, 97-122"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@detectXSS"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)<script[^>]*>[sS]*?"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i).(?:b(?:x(?:link:href|html|mlns)|data:text/html|formaction|patternb.*?=)|!ENTITY[sv]+(?:%[sv]+)?[^sv]+[sv]+(?:SYSTEM|PUBLIC)|@import|;base64)b"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)[a-z]+=(?:[^:=]+:.+;)*?[^:=]+:url(javascript"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)<[^0-9<>A-Z_a-z]*(?:[^sv\"'<>]*:)?[^0-9<>A-Z_a-z]*[^0-9A-Z_a-z]*?(?:s[^0-9A-Z_a-z]*?(?:c[^0-9A-Z_a-z]*?r[^0-9A-Z_a-z]*?i[^0-9A-Z_a-z]*?p[^0-9A-Z_a-z]*?t|t[^0-9A-Z_a-z]*?y[^0-9A-Z_a-z]*?l[^0-9A-Z_a-z]*?e|v[^0-9A-Z_a-z]*?g|e[^0-9A-Z_a-z]*?t[^0-9>A-Z_a-z])|f[^0-9A-Z_a-z]*?o[^0-9A-Z_a-z]*?r[^0-9A-Z_a-z]*?m|m[^0-9A-Z_a-z]*?(?:a[^0-9A-Z_a-z]*?r[^0-9A-Z_a-z]*?q[^0-9A-Z_a-z]*?u[^0-9A-Z_a-z]*?e[^0-9A-Z_a-z]*?e|e[^0-9A-Z_a-z]*?t[^0-9A-Z_a-z]*?a[^0-9>A-Z_a-z])|(?:l[^0-9A-Z_a-z]*?i[^0-9A-Z_a-z]*?n[^0-9A-Z_a-z]*?k|o[^0-9A-Z_a-z]*?b[^0-9A-Z_a-z]*?j[^0-9A-Z_a-z]*?e[^0-9A-Z_a-z]*?c[^0-9A-Z_a-z]*?t|e[^0-9A-Z_a-z]*?m[^0-9A-Z_a-z]*?b[^0-9A-Z_a-z]*?e[^0-9A-Z_a-z]*?d|a[^0-9A-Z_a-z]*?(?:p[^0-9A-Z_a-z]*?p[^0-9A-Z_a-z]*?l[^0-9A-Z_a-z]*?e[^0-9A-Z_a-z]*?t|u[^0-9A-Z_a-z]*?d[^0-9A-Z_a-z]*?i[^0-9A-Z_a-z]*?o|n[^0-9A-Z_a-z]*?i[^0-9A-Z_a-z]*?m[^0-9A-Z_a-z]*?a[^0-9A-Z_a-z]*?t[^0-9A-Z_a-z]*?e)|p[^0-9A-Z_a-z]*?a[^0-9A-Z_a-z]*?r[^0-9A-Z_a-z]*?a[^0-9A-Z_a-z]*?m|i?[^0-9A-Z_a-z]*?f[^0-9A-Z_a-z]*?r[^0-9A-Z_a-z]*?a[^0-9A-Z_a-z]*?m[^0-9A-Z_a-z]*?e|b[^0-9A-Z_a-z]*?(?:a[^0-9A-Z_a-z]*?s[^0-9A-Z_a-z]*?e|o[^0-9A-Z_a-z]*?d[^0-9A-Z_a-z]*?y|i[^0-9A-Z_a-z]*?n[^0-9A-Z_a-z]*?d[^0-9A-Z_a-z]*?i[^0-9A-Z_a-z]*?n[^0-9A-Z_a-z]*?g[^0-9A-Z_a-z]*?s)|i[^0-9A-Z_a-z]*?m[^0-9A-Z_a-z]*?a?[^0-9A-Z_a-z]*?g[^0-9A-Z_a-z]*?e?|v[^0-9A-Z_a-z]*?i[^0-9A-Z_a-z]*?d[^0-9A-Z_a-z]*?e[^0-9A-Z_a-z]*?o)[^0-9>A-Z_a-z])|(?:<[0-9A-Z_a-z].*[sv/]|[\" ' ] ( ? : . * [ s v / ] ) ? ) ( ? : b a c k g r o u n d | f o r m a c t i o n | l o w s r c | o n ( ? : a ( ? : b o r t | c t i v a t e | d ( ? : a p t e r a d d e d | d t r a c k ) | f t e r ( ? : p r i n t | ( ? : s c r i p t e x e c u | u p d a ) t e ) | l e r t i n g | n ( ? : i m a t i o n ( ? : c a n c e l | e n d | i t e r a t i o n | s t a r t ) | t e n n a s t a t e c h a n g e ) | p p c o m m a n d | u ( ? : d i o ( ? : e n d | p r o c e s s | s t a r t ) | x c l i c k ) ) | b ( ? : e ( ? : f o r e ( ? : ( ? : ( ? : ( ? : d e ) ? a c t i v a | s c r i p t e x e c u ) t | t o g g l ) e | c ( ? : o p y | u t ) | e d i t f o c u s | i n p u t | p ( ? : a s t e | r i n t ) | u ( ? : n l o a d | p d a t e ) ) | g i n ( ? : E v e n t ) ? ) | l ( ? : o c k e d | u r ) | o u n ( ? : c e | d a r y ) | r o a d c a s t | u s y ) | c ( ? : a ( ? : ( ? : c h | l l s c h a n g ) e d | n p l a y ( ? : t h r o u g h ) ? | r d s t a t e c h a n g e ) | ( ? : e l l | f s t a t e ) c h a n g e | h ( ? : a ( ? : r g i n g ( ? : t i m e ) ? c h a ) ? n g e | e c k i n g ) | l ( ? : i c k | o s e ) | o ( ? : m ( ? : m a n d ( ? : u p d a t e ) ? | p ( ? : l e t e | o s i t i o n ( ? : e n d | s t a r t | u p d a t e ) ) ) | n ( ? : n e c t ( ? : e d | i n g ) | t ( ? : e x t m e n u | r o l s e l e c t ) ) | p y ) | u ( ? : e c h a n g e | t ) ) | d ( ? : a t a ( ? : ( ? : a v a i l a b l | c h a n g ) e | e r r o r | s e t c ( ? : h a n g e d | o m p l e t e ) ) | b l c l i c k | e ( ? : a c t i v a t e | l i v e r y ( ? : e r r o r | s u c c e s s ) | v i c e ( ? : f o u n d | l i g h t | ( ? : m o | o r i e n t a ) t i o n | p r o x i m i t y ) ) | i ( ? : a l i n g | s ( ? : a b l e d | c ( ? : h a r g i n g t i m e c h a n g e | o n n e c t ( ? : e d | i n g ) ) ) ) | o ( ? : m ( ? : a ( ? : c t i v a t e | t t r m o d i f i e d ) | ( ? : c h a r a c t e r d a t a | s u b t r e e ) m o d i f i e d | f o c u s ( ? : i n | o u t ) | m o u s e s c r o l l | n o d e ( ? : i n s e r t e d ( ? : i n t o d o c u m e n t ) ? | r e m o v e d ( ? : f r o m d o c u m e n t ) ? ) ) | w n l o a d i n g ) | r ( ? : a g ( ? : d r o p | e ( ? : n ( ? : d | t e r ) | x i t ) | ( ? : g e s t u r | l e a v ) e | o v e r | s t a r t ) | o p ) | u r a t i o n c h a n g e ) | e ( ? : m p t i e d | n ( ? : a b l e d | d ( ? : e d | E v e n t ) ? | t e r ) | r r o r ( ? : u p d a t e ) ? | x i t ) | f ( ? : a i l e d | i ( ? : l t e r c h a n g e | n i s h ) | o ( ? : c u s ( ? : i n | o u t ) ? | r m ( ? : c h a n g e | i n p u t ) ) | u l l s c r e e n c h a n g e ) | g ( ? : a m e p a d ( ? : a x i s m o v e | b u t t o n ( ? : d o w n | u p ) | ( ? : d i s ) ? c o n n e c t e d ) | e t ) | h ( ? : a s h c h a n g e | e ( ? : a d p h o n e s c h a n g e | l [ d p ] ) | o l d i n g ) | i ( ? : c c ( ? : c a r d l o c k e r r o r | i n f o c h a n g e ) | n ( ? : c o m i n g | p u t | v a l i d ) ) | k e y ( ? : d o w n | p r e s s | u p ) | l ( ? : e v e l c h a n g e | o ( ? : a d ( ? : e ( ? : d ( ? : m e t a ) ? d a t a | n d ) | s t a r t ) ? | s e c a p t u r e ) | y ) | m ( ? : a r k | e s s a g e | o ( ? : u s e ( ? : d o w n | e n t e r | ( ? : l e a | m o ) v e | o ( ? : u t | v e r ) | u p | w h e e l ) | v e ( ? : e n d | s t a r t ) ? | z ( ? : a ( ? : f t e r p a i n t | u d i o a v a i l a b l e ) | ( ? : b e f o r e r e s i z | o r i e n t a t i o n c h a n g | t ( ? : a p g e s t u r | i m e c h a n g ) ) e | ( ? : e d g e u i ( ? : c ( ? : a n c e l | o m p l e t ) | s t a r t ) e | n e t w o r k ( ? : d o w n | u p ) l o a ) d | f u l l s c r e e n ( ? : c h a n g e | e r r o r ) | m ( ? : a g n i f y g e s t u r e ( ? : s t a r t | u p d a t e ) ? | o u s e ( ? : h i t t e s t | p i x e l s c r o l l ) ) | p ( ? : o i n t e r l o c k ( ? : c h a n g e | e r r o r ) | r e s s t a p g e s t u r e ) | r o t a t e g e s t u r e ( ? : s t a r t | u p d a t e ) ? | s ( ? : c r o l l e d a r e a c h a n g e d | w i p e g e s t u r e ( ? : e n d | s t a r t | u p d a t e ) ? ) ) ) ) | n o ( ? : m a t c h | u p d a t e ) | o ( ? : ( ? : b s o l e t | ( ? : f f | n ) l i n ) e | p e n | v e r f l o w ( ? : c h a n g e d ) ? ) | p ( ? : a ( ? : g e ( ? : h i d e | s h o w ) | i n t | ( ? : s t | u s ) e ) | l a y ( ? : i n g ) ? | o ( ? : i n t e r ( ? : d o w n | e n t e r | ( ? : ( ? : l e a | m o ) v | r a w u p d a t ) e | o ( ? : u t | v e r ) | u p ) | p ( ? : s t a t e | u p ( ? : h i d ( ? : d e n | i n g ) | s h o w ( ? : i n g | n ) ) ) ) | r o ( ? : g r e s s | p e r t y c h a n g e ) ) | r ( ? : a t e c h a n g e | e ( ? : a d y s t a t e c h a n g e | c e i v e d | m o v e t r a c k | p e a t ( ? : E v e n t ) ? | q u e s t | s ( ? : e t | i z e | u ( ? : l t | m ( ? : e | i n g ) ) ) | t r i e v i n g ) | o w ( ? : e ( ? : n t e r | x i t ) | s ( ? : d e l e t e | i n s e r t e d ) ) ) | s ( ? : c r o l l ( ? : e n d ) ? | e ( ? : a r c h | e k ( ? : c o m p l e t e | e d | i n g ) | l e c t ( ? : i o n c h a n g e | s t a r t ) ? | n ( ? : d i n g | t ) | t ) | h o w | ( ? : o u n d | p e e c h ) ( ? : e n d | s t a r t ) | t ( ? : a ( ? : l l e d | r t | t ( ? : e c h a n g e | u s c h a n g e d ) ) | k ( ? : c o m m a | s e s s i o n e ) n d | o p ) | u ( ? : b m i t | c c e s s | s p e n d ) | v g ( ? : a b o r t | e r r o r | ( ? : u n ) ? l o a d | r e s i z e | s
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)(?:W|^)(?:javascript:(?:[sS]+[=x5c([.<]|[sS]*?(?:bnameb|x5c[ux]d))|data:(?:(?:[a-z]w+/w[w+-]+w)?[;,]|[sS]*?;[sS]*?b(?:base64|charset=)|[sS]*?,[sS]*?<[sS]*?w[sS]*?>))|@W*?iW*?mW*?pW*?oW*?rW*?tW*?(?:/*[sS]*?)?(?:[\"']|W*?uW*?rW*?l[sS]*?()|[^-]*?-W*?mW*?oW*?zW*?-W*?bW*?iW*?nW*?dW*?iW*?nW*?g[^:]*?:W*?uW*?rW*?l[sS]*?("
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@pm document.cookie document.domain document.write .parentnode .innerhtml window.location -moz-binding <!-- <![cdata["
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i:<style.*?>.*?(?:@[ix5c]|(?:[:=]|&#x?0*(?:58|3A|61|3D);?).*?(?:[(x5c]|&#x?0*(?:40|28|92|5C);?)))"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i:<.*[:]?vmlframe.*?[s/+]*?src[s/+]*=)"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)(?:j|&#(?:0*(?:74|106)|x0*[46]A);)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:a|&#(?:0*(?:65|97)|x0*[46]1);)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:v|&#(?:0*(?:86|118)|x0*[57]6);)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:a|&#(?:0*(?:65|97)|x0*[46]1);)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:s|&#(?:0*(?:115|83)|x0*[57]3);)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:c|&#(?:x0*[46]3|0*(?:99|67));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:r|&#(?:x0*[57]2|0*(?:114|82));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:i|&#(?:x0*[46]9|0*(?:105|73));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:p|&#(?:x0*[57]0|0*(?:112|80));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:t|&#(?:x0*[57]4|0*(?:116|84));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?::|&(?:#(?:0*58|x0*3A);?|colon;))."
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)(?:v|&#(?:0*8|x0*5)[36];)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:b|&#(?:0*6[26]|x0*(?:98|42));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:s|&#(?:0*(?:115|83)|x0*[57]3);)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:c|&#(?:x0*[46]3|0*(?:99|67));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:r|&#(?:x0*[57]2|0*(?:114|82));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:i|&#(?:x0*[46]9|0*(?:105|73));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:p|&#(?:x0*[57]0|0*(?:112|80));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?:t|&#(?:x0*[57]4|0*(?:116|84));)(?:[t-nr]|&(?:#(?:0*(?:9|1[03])|x0*[AD]);?|(?:tab|newline);))*(?::|&(?:#(?:0*58|x0*3A);?|colon;))."
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)<EMBED[s/+].*?(?:src|type).*?="
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx <[?]?import[s/+S]*?implementation[s/+]*?="
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i:<META[s/+].*?http-equiv[s/+]*=[s/+]*[\"'`]?(?:(?:c|&#x?0*(?:67|43|99|63);?)|(?:r|&#x?0*(?:82|52|114|72);?)|(?:s|&#x?0*(?:83|53|115|73);?)))"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i:<META[s/+].*?charset[s/+]*=)"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)<LINK[s/+].*?href[s/+]*="
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)<BASE[s/+].*?href[s/+]*="
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)<APPLET[s/+>]"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)<OBJECT[s/+].*?(?:type|codetype|classid|code|data)[s/+]*="
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx xbc[^xbe>]*[xbe>]|<[^xbe]*xbe"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?:xbcs*/s*[^xbe>]*[xbe>])|(?:<s*/s*[^xbe]*xbe)"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx +ADw-.*(?:+AD4-|>)|<.*+AD4-"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx ![!+ ][]"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?:self|document|this|top|window)s*(?:/*|[[)]).+?(?:]|*/)"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)b(?:eval|set(?:timeout|interval)|new[sv]+Function|a(?:lert|tob)|btoa)[sv]*("
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx ((?:[[^]]*][^.]*.)|Reflect[^.]*.).*(?:map|sort|apply)[^.]*..*call[^`]*`.*`"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@lt 2"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@lt 2"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@detectXSS"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)[s\"'`;/0-9=x0Bx09x0Cx3Bx2Cx28x3B]on[a-zA-Z]{3,25}[sx0Bx09x0Cx3Bx2Cx28x3B]*?=[^=]"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)b(?:s(?:tyle|rc)|href)b[sS]*?="
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@contains -->"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx <(?:a|abbr|acronym|address|applet|area|audioscope|b|base|basefront|bdo|bgsound|big|blackface|blink|blockquote|body|bq|br|button|caption|center|cite|code|col|colgroup|comment|dd|del|dfn|dir|div|dl|dt|em|embed|fieldset|fn|font|form|frame|frameset|h1|head|hr|html|i|iframe|ilayer|img|input|ins|isindex|kdb|keygen|label|layer|legend|li|limittext|link|listing|map|marquee|menu|meta|multicol|nobr|noembed|noframes|noscript|nosmartquotes|object|ol|optgroup|option|p|param|plaintext|pre|q|rt|ruby|s|samp|script|select|server|shadow|sidebar|small|spacer|span|strike|strong|style|sub|sup|table|tbody|td|textarea|tfoot|th|thead|title|tr|tt|u|ul|var|wbr|xml|xmp)W"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i:[\"'][ ]*(?:[^a-z0-9~_:' ]|in).*?(?:(?:l|x5cu006C)(?:o|x5cu006F)(?:c|x5cu0063)(?:a|x5cu0061)(?:t|x5cu0074)(?:i|x5cu0069)(?:o|x5cu006F)(?:n|x5cu006E)|(?:n|x5cu006E)(?:a|x5cu0061)(?:m|x5cu006D)(?:e|x5cu0065)|(?:o|x5cu006F)(?:n|x5cu006E)(?:e|x5cu0065)(?:r|x5cu0072)(?:r|x5cu0072)(?:o|x5cu006F)(?:r|x5cu0072)|(?:v|x5cu0076)(?:a|x5cu0061)(?:l|x5cu006C)(?:u|x5cu0075)(?:e|x5cu0065)(?:O|x5cu004F)(?:f|x5cu0066)).*?=)"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx (?i)[\"'][ ]*(?:[^a-z0-9~_:' ]|in).+?[.].+?="
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
"pattern" : "@rx {{.*?}}"
2025-02-25 00:26:42 +00:00
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 3"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 3"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 4"
} ,
{
2025-02-26 00:26:24 +00:00
"category" : "XSS" ,
2025-02-25 00:26:42 +00:00
"pattern" : "@lt 4"
} ,
{
"category" : "IIS" ,
"pattern" : "@lt 1"
} ,
{
"category" : "IIS" ,
"pattern" : "@lt 1"
} ,
{
"category" : "IIS" ,
"pattern" : "@rx [a-z]:x5cinetpubb"
} ,
{
"category" : "IIS" ,
"pattern" : "@rx (?:Microsoft OLE DB Provider for SQL Server(?:</font>.{1,20}?error '800(?:04005|40e31)'.{1,40}?Timeout expired| (0x80040e31)<br>Timeout expired<br>)|<h1>internal server error</h1>.*?<h2>part of the server has crashed or it has a configuration error.</h2>|cannot connect to the server: timed out)"
} ,
{
"category" : "IIS" ,
"pattern" : "@pmFromFile iis-errors.data"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "IIS" ,
"pattern" : "!@rx ^404$"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "IIS" ,
"pattern" : "@rx bServer Error in.{0,50}?bApplicationb"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "IIS" ,
2025-02-22 10:52:46 +00:00
"pattern" : "@lt 2"
2025-02-08 00:25:04 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "IIS" ,
2025-02-08 00:25:04 +00:00
"pattern" : "@lt 2"
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "IIS" ,
2025-02-08 00:25:04 +00:00
"pattern" : "@lt 3"
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "IIS" ,
2025-02-08 00:25:04 +00:00
"pattern" : "@lt 3"
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "IIS" ,
2025-02-08 00:25:04 +00:00
"pattern" : "@lt 4"
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "IIS" ,
2025-02-08 00:25:04 +00:00
"pattern" : "@lt 4"
} ,
2025-02-04 00:25:09 +00:00
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 1"
2025-01-30 00:24:54 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 1"
2025-01-30 00:24:54 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 2"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 2"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 3"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 3"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 4"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 4"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 1"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 1"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 2"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 2"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 3"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 3"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 4"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge 4"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge %{tx.outbound_anomaly_score_threshold}"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@eq 1"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@ge %{tx.outbound_anomaly_score_threshold}"
2025-02-22 10:52:46 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 1"
} ,
{
"category" : "EVALUATION" ,
"pattern" : "@lt 1"
} ,
{
"category" : "EVALUATION" ,
2025-02-22 10:52:46 +00:00
"pattern" : "@lt 2"
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
2025-02-22 10:52:46 +00:00
"pattern" : "@lt 2"
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 3"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 3"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 4"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "EVALUATION" ,
"pattern" : "@lt 4"
2025-02-23 00:28:29 +00:00
} ,
2025-02-26 00:26:24 +00:00
{
"category" : "CORRELATION" ,
"pattern" : "@eq 0"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@ge 5"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@eq 0"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@ge %{tx.inbound_anomaly_score_threshold}"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@ge %{tx.outbound_anomaly_score_threshold}"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 2"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@ge %{tx.inbound_anomaly_score_threshold}"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@ge %{tx.outbound_anomaly_score_threshold}"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 3"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@gt 0"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 4"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 1"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 1"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 2"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 2"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 3"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 3"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 4"
} ,
{
"category" : "CORRELATION" ,
"pattern" : "@lt 4"
} ,
{
"category" : "PHP" ,
"pattern" : "@lt 1"
} ,
{
"category" : "PHP" ,
"pattern" : "@lt 1"
} ,
{
"category" : "PHP" ,
"pattern" : "@pmFromFile php-errors.data"
} ,
{
"category" : "PHP" ,
"pattern" : "@rx (?:b(?:f(?:tp_(?:nb_)?f?(?:ge|pu)t|get(?:s?s|c)|scanf|write|open|read)|gz(?:(?:encod|writ)e|compress|open|read)|s(?:ession_start|candir)|read(?:(?:gz)?file|dir)|move_uploaded_file|(?:proc_|bz)open|call_user_func)|$_(?:(?:pos|ge)t|session))b"
} ,
{
"category" : "PHP" ,
"pattern" : "@rx (?i)<?(?:=|php)?s+"
} ,
{
"category" : "PHP" ,
"pattern" : "@lt 2"
} ,
{
"category" : "PHP" ,
"pattern" : "@lt 2"
} ,
{
"category" : "PHP" ,
"pattern" : "@pmFromFile php-errors-pl2.data"
} ,
{
"category" : "PHP" ,
"pattern" : "@lt 3"
} ,
{
"category" : "PHP" ,
"pattern" : "@lt 3"
} ,
{
"category" : "PHP" ,
"pattern" : "@lt 4"
} ,
{
"category" : "PHP" ,
"pattern" : "@lt 4"
} ,
2025-02-23 00:28:29 +00:00
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@lt 1"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@lt 1"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@pmFromFile web-shells-php.data"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx (<title>r57 Shell Version [0-9.]+</title>|<title>r57 shell</title>)"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^<html><head><meta http-equiv='Content-Type' content='text/html; charset=Windows-1251'><title>.*? - WSO [0-9.]+</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx B4TM4N SH3LL</title>.*<meta name='author' content='k4mpr3t'/>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx <title>Mini Shell</title>.*Developed By LameHacker"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx <title>.:: .* ~ Ashiyane V [0-9.]+ ::.</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx <title>Symlink_Sa [0-9.]+</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx <title>CasuS [0-9.]+ by MafiABoY</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^<html>rn<head>rn<title>GRP WebShell [0-9.]+"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx <small>NGHshell [0-9.]+ by Cr4sh</body></html>n$"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx <title>SimAttacker - (?:Version|Vrsion) : [0-9.]+ -"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^<!DOCTYPE html>n<html>n<!-- By Artyum .*<title>Web Shell</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx <title>lama's'hell v. [0-9.]+</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^ *<html>n[ ]+<head>n[ ]+<title>lostDC -"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^<title>PHP Web Shell</title>rn<html>rn<body>rn <!-- Replaces command with Base64-encoded Data -->"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^<html>n<head>n<div align=\"left\"><font size=\"1\">Input command :</font></div>n<form name=\"cmd\" method=\"POST\" enctype=\"multipart/form-data\">"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^<html>n<head>n<title>Ru24PostWebShell -"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx <title>s72 Shell v[0-9.]+ Codinf by Cr@zy_King</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^<html>rn<head>rn<meta http-equiv=\"Content-Type\" content=\"text/html; charset=gb2312\">rn<title>PhpSpy Ver [0-9]+</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^ <html>nn<head>nn<title>g00nshell v[0-9.]+"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@contains <title>punkholicshell</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^<html>n <head>n <title>azrail [0-9.]+ by C-W-M</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx >SmEvK_PaThAn Shell v[0-9]+ coded by <a href="
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^<html>n<title>.*? ~ Shell I</title>n<head>n<style>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@rx ^ <html><head><title>:: b374k m1n1 [0-9.]+ ::</title>"
2025-02-23 00:28:29 +00:00
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
"pattern" : "@lt 2"
} ,
{
"category" : "SHELLS" ,
"pattern" : "@lt 2"
} ,
{
"category" : "SHELLS" ,
"pattern" : "@contains <h1 style=\"margin-bottom: 0\">webadmin.php</h1>"
} ,
{
"category" : "SHELLS" ,
"pattern" : "@lt 3"
} ,
{
"category" : "SHELLS" ,
"pattern" : "@lt 3"
} ,
{
"category" : "SHELLS" ,
2025-02-23 00:28:29 +00:00
"pattern" : "@lt 4"
} ,
{
2025-02-25 00:26:42 +00:00
"category" : "SHELLS" ,
2025-02-23 00:28:29 +00:00
"pattern" : "@lt 4"
2024-12-21 01:02:34 +01:00
}
2024-12-21 01:02:14 +00:00
]