>shellcode rules
I din't talk about shellcode, but an entire spyware injected in the browser through a 0day.
For the encrypted traffic I was thinking to capture the traffic with mitmproxy then maybe pipe it in snort... but if it can't detect injection is absolutely unuseful.