I came into work to see a bunch of these populating in the Monitor tab.

Apparently, IPS will stop the attack at first via Content ID engine. However, if you fragment the SMB packet it will fail to do so.

Upon further investigation I was able to confirm that a remote shell can be achieved without detection from the threat logs. I had to pass on the information to our systems admin since I’m an overworked network engineer. Security is going to be thrilled.
