'; } else{ echo ''; } echo '
|
|||
Rule General Information |
---|
Release Date: | 2025-08-05 | |
Rule Name: | Tool VShell Detection - Websocket Online | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Vshell is a comprehensive red team tool designed with both stealth and flexibility in mind, making it especially suitable for simulating network attacks and testing defense systems. The tool supports a wide range of protocols, including TCP, UDP, KCP, WebSocket, DNS, DoH, and DoT. It comes with built-in tunneling and proxy capabilities, supporting both forward and reverse connection modes to adapt to complex network environments. Its core features include file management, forward/reverse connection for agent deployment, plugin execution, and tunneling proxy functionalities.This rule is used to detect VShell C2 tool Websocket Online traffic. | |
Impact: | Attackers use attack tools to attack targets, which can lead to data leakage, service interruption, system crash, data tampering, and illegal access. | |
Affected OS: | Windows, Linux, Others | |
Reference: | ||
Solutions |
---|
1. Scan the server file system to ensure that no hacking tools and related malicious files are left. 2. Make a complete system backup to ensure the security of server data. 3. Secure the server, restrict access rights, install firewalls, and use secure access control lists. |