CVE-2019-0708 BlueKeep RDP Exploit Attempt
Detects network activity characteristic of the CVE-2019-0708 (BlueKeep) Remote Desktop Services exploit, including specific RDP negotiation patterns and subsequent RDP service crashes or resets potentially indicative of a successful or failed exploitation attempt.
Suricata

