Squidbleed Vulnerability - FTP Default Configuration Exploitation
Detects attempts to exploit the Squidbleed vulnerability by monitoring 'squid.exe' process command lines for keywords related to FTP default configuration exploitation, specifically 'Safe_ports', 'CONNECT', 'PORT', 'PASV', '21', and 'tcp_outgoing_address'. This indicates an adversary trying to bypass security controls or exfiltrate data via FTP.
Microsoft Sentinel (KQL)

