NetWare Directory Listing Format Detection
This rule detects network connections on port 21 (FTP) where the remote URL contains keywords indicative of NetWare directory listings or related services (netware, NDS, bindery, ncf). This could indicate an attempt to discover or interact with NetWare services, potentially exploiting vulnerabilities like Squidbleed.
SentinelOne

