Squidbleed Vulnerability - Heap Buffer Overread Signature
This rule detects potential exploitation attempts related to the Squidbleed vulnerability, specifically looking for command-line arguments indicative of heap buffer overread conditions within the 'squid.exe' process. It monitors for keywords such as 'strchr', 'buffer', 'overread', 'parse', 'directory', and 'listing' in the command line.
Microsoft Sentinel (KQL)

