Netskope Threat Labs

FILE-OTHER Metasploit archive tar arb file write

IPS-SWG

1 SID: 140736

First seen
June 2022
Last seen
October 2026

Detects an archive exploiting CVE-2020-28949, the Perl archive module flaw used by a Metasploit module to write files outside the extraction directory. The rule matches the crafted traversal structures that the exploit uses to plant files on the target.