XSS Attack Attempt - JavaScript Injection in HTTP URI or POST Body
This rule detects attempts to inject malicious JavaScript code via HTTP URI requests. It uses PCRE pattern matching to identify common XSS indicators such as <script> tags, JavaScript event handlers (onerror, onload), and attempts to access document.cookie, which are indicative of stored or reflected Cross-Site Scripting (XSS) attack patterns.
Suricata

