Description
Detects SVG image content in transit, through either an XML DOCTYPE preamble (SID 150001) or the SVG root element tag within the first bytes (SID 150020). The rules never alert on their own; they set the file.svg marker so downstream exploit and inspection rules can condition alerts on an SVG being present in the session. Crafted SVGs can carry embedded scripts or smuggled payloads behind a DOCTYPE, which makes the marker useful for gating policy.