Squidbleed Vulnerability - FTP Passive Mode Abuse (PASV Command)
This rule detects potential exploitation of the Squidbleed vulnerability by identifying network connections to FTP port 21 where the remote URL contains 'PASV' or 'EPSV' commands, and the initiating process is 'squid.exe'. This indicates an attempt to abuse FTP passive mode through the Squid proxy.
Microsoft Sentinel (KQL)

