diff --git a/network/detection/smb-detect.yaml b/network/detection/smb-detect.yaml deleted file mode 100644 index cf3c61f95e..0000000000 --- a/network/detection/smb-detect.yaml +++ /dev/null @@ -1,27 +0,0 @@ -id: smb-detect - -info: - name: SMB Detection - author: pussycat0x - severity: low - description: | - SMB (Server Message Block) is a network-layered protocol mainly used on Windows for sharing files, printers, and communication between network-attached computers. SMB related vulnerabilities can be levaraged to compromise large-scale systems. - metadata: - max-request: 1 - tags: network,windows,linux,smb,service,detect - -tcp: - - inputs: - - data: 00000031ff534d4272000000001845680000000000000000000000000000be2200000100000e00024e54204c4d20302e3132000200 - type: hex - - host: - - "{{Hostname}}" - port: 445 - - matchers: - - type: word - words: - - "SMBr" - - "NT LM" - condition: or