Description
Detects PDF document content in transit by its header signature. The rules never alert on their own; they set the file.pdf marker so downstream exploit and inspection rules can condition alerts on a PDF being present in the session, a common malware delivery format.