RULE(RULE ID:331419)

Rule General Information
Release Date: 2020-12-10
Rule Name: FireEye Red Team Tool Backdoor CSBundle NYTIMES GET
Severity:
CVE ID:
Rule Protection Details
Description: FireEye is a network security company that provides advanced threat detection and malware protection. On December 8, 2020, FireEye announced that it had been attacked by a professional APT organization, resulting in the theft of its Red Team tools. With these tools attackers may pose a great threat to the enterprise. This rule is used to detect the traffic of FireEye Red Team tools.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html
Solutions
Please contact the software vendor to update the software patch.