Squidbleed Vulnerability - FTP Traffic on Non-Standard Port 21
Detects FTP protocol traffic (on port 21) initiated by a process named 'squid.exe' or containing 'squid' in its filename. This rule is designed to identify potential exploitation attempts related to the Squidbleed vulnerability, where a compromised Squid proxy might be used for unauthorized FTP communications.
Microsoft Sentinel (KQL)

