HTTP Directory Traversal Path Traversal Attack via URI Sequences
This rule detects attempts to perform directory traversal attacks by monitoring incoming HTTP requests for repetitive directory navigation sequences (e.g., ../, .., %2F, %5C). Such sequences are often used to bypass security controls and access unauthorized files or directories on the web server.
Suricata

