Description
Detects Windows enhanced metafile (EMF) content in transit by its header signature. The rules never alert on their own; they set the file.emf marker so downstream exploit and inspection rules can condition alerts on an EMF file being present in the session, since crafted metafiles have historically reached vulnerable graphics parsers.