Dear fellow Check Mates!
We had once again a case where the IPS was preventing some production traffic. In order to find the root cause, we would need to understand what exactly is checked by a certain protection and what trigger conditions are used by that protection.
Is there any source where such details are documented?
Other products or tools (like e.g. Snort) provide repositories with the actual patterns and thresholds.
For the current case, we are looking for the protection 'PHP Web Shell Generic Backdoor' (CPAI-2014-2299), which was definitely triggering on some none PHP web server related communication. But we had other cases in the past as well.
Any hint or idea is much appreciated. Thank you very much in advance for your response.
Best Regards,
Ralf