Process Injection Staging - PE Header in HTTP Response Stream (T1055.003)
Detects the transmission of a Portable Executable (PE) file header ('MZ' and 'PE' magic bytes) within an HTTP response stream, which is a common indicator of a staged file download or process injection payload being delivered over the network.
Suricata

