'; } else{ echo ''; } echo '
|
|||
Rule General Information |
---|
Release Date: | 2025-08-05 | |
Rule Name: | Tool XiebroC2 Detection - TCP Keepalive | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Xiebro is a C2 development framework built with Golang and .NET, designed to support multiple users and multiple servers. It supports various communication protocols, including TCP and WebSocket, and typically uses AES encryption for communications between the client and the Xiebro server to ensure security and stealth.This rule is used to detect TCP keep-alive traffic generated by the XiebroC2 tool. | |
Impact: | Attackers use attack tools to attack targets, which can lead to data leakage, service interruption, system crash, data tampering, and illegal access. | |
Affected OS: | Windows, Linux, Others | |
Reference: | ||
Solutions |
---|
1. Scan the server file system to ensure that no hacking tools and related malicious files are left. 2. Make a complete system backup to ensure the security of server data. 3. Secure the server, restrict access rights, install firewalls, and use secure access control lists. |