Metasploit Meterpreter Reverse HTTPS C2 - Random SNI on High Port
Detects outbound HTTPS traffic on high ports where the TLS SNI header consists of a 8-20 character random alphanumeric string. This pattern is indicative of default configurations for Metasploit Meterpreter Reverse HTTPS payloads attempting to establish a Command and Control connection.
Suricata

