Closed deadbits closed 1 year ago
rule MarkdownExfiltration { meta: category = "Data Exfiltration" description = "Detects Markdown image with query parameters used during data exfiltration" author = "Adam M. Swanda" references = "https://embracethered.com/blog/posts/2023/bing-chat-data-exfiltration-poc-and-fix/" strings: $md = /\!\[.+]\(https?://[a-z\.]+/logo\.png\?q=.+\)/ condition: $md }
something like that but better regex
https://github.com/deadbits/vigil-llm/blob/main/data/yara/mdexfil.yar
something like that but better regex