CVE-2025-60727 Malicious XLSX Attachment Delivery via SMTP
Detects SMTP traffic containing XLSX file attachments, specifically looking for base64 encoded content that matches the criteria for CVE-2025-60727. This rule monitors network traffic for the delivery of potential malicious Office documents.
Suricata

