Metasploit Meterpreter Reverse TCP TLV Handshake Strings

This rule monitors for known string patterns associated with the initialization and command execution of the Metasploit Meterpreter reverse TCP payload. By inspecting network traffic for characteristic C2 handshake and command strings, it identifies active Meterpreter sessions.