@james_inthe_box@infosec.exchange
Post #3863642
2026-07-16 17:02 UTC
Got tired of mucking with these miserable #screenconnect msi's so here's a #suricata rule to catch the initial check via sni:
https://gist.github.com/silence-is-best/29afec335264313e9bf5bfa1c6e60144
https://app.any.run/tasks/73887f39-a8ac-4702-a67d-36465caca294
cc @da_667@infosec.exchange
Replies (2)
-
@da_667@infosec.exchange 2026-07-16 18:00
@james_inthe_box@infosec.exchange thank you for this! Going to create DNS and TLS SNI rules for this domain. Also noticing we don't have coverage for other screenconnect domains as well... https://lolrmm.io/tools/screenconnect
-
@netresec@infosec.exchange 2026-07-21 20:36
@james_inthe_box@infosec.exchange @da_667@infosec.exchange Nice! Another alternative is to use FlowCarp. It has really good detection for ScreenConnect in TLS. Here's the output from the free FlowCarp demo service.