Quiz 4 Question 1 of 20

An analyst is building a Suricata detection rule for a known exploit that sends a specific 8-byte magic value at offset 0 in a TCP payload on port 9001. Which rule syntax correctly captures this?

Select an answer to reveal the explanation.

Motivation