alert http any any -> $HOME_NET any (msg:"ATTACK 'Polly for Sonya' Cyrillic-language Docker pwn tooling marker"; \
flow:to_server,established; \
http.method; content:"POST"; \
http.request_body; content:"by Polly for"; \
classtype:attempted-admin; sid:1000231006; rev:1; \
metadata:created_at 2026-05-28;)Ingress · any port · SID 1000231006
A tighter, lower-volume signature for the exact tooling observed here: the `by Polly for` attribution byline in a request body.