Large FTP Response with Stale Data (Squidbleed Vulnerability)

Detects unusually large FTP responses containing 'LIST' or 'NLST' commands, potentially indicating an attempt to exploit the Squidbleed vulnerability or similar data exfiltration over FTP. The rule specifically looks for network events on port 21 (FTP) where the action type is 'NetworkSignatureInspected' and the RemoteUrl contains either 'LIST' or 'NLST' with a string length greater than 4000 characters.