FTP LIST Response with Malformed Directory Entries
This rule detects network events where an FTP LIST response contains malformed directory entries, potentially indicating an attempt to exploit the Squidbleed vulnerability. It specifically looks for network signature inspections on port 21 (FTP) with common FTP commands (LIST, NLST, MLSD, MLST, RETR) in the RemoteUrl, while excluding common log and text file extensions.
Microsoft Sentinel (KQL)

