alert tcp any any -> any any (msg:"Hydra爆破攻击"; flow:to_server; content:"User-Agent"; content:"Hydra"; nocase; distance:0; within:50; fast_pattern; metadata:service http; metadata:service http; sid:1; rev:1;) alert tcp any any -> any any (msg:"WPScan扫描攻击"; flow:to_server; content:"User-Agent|3a| WPScan"; nocase; http_header; pcre:"/User-Agent:[^\x0a\x0d]*?(wpscan\.org|WPScan)/iH"; metadata:service http; sid:2; rev:1;)
Hydra
alert tcp any any -> any any (msg:"Hydra爆破攻击"; flow:to_server; content:"User-Agent"; content:"Hydra"; nocase; distance:0; within:50; fast_pattern; metadata:service http; metadata:service http; sid:1; rev:1;)
alert tcp any any -> any any (msg:"WPScan扫描攻击"; flow:to_server; content:"User-Agent|3a| WPScan"; nocase; http_header; pcre:"/User-Agent:[^\x0a\x0d]*?(wpscan\.org|WPScan)/iH"; metadata:service http; sid:1; rev:1;)