Techniques › T1190
T1190 Exploit Public-Facing Application
initial access — Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
7
analytics
149
Sigma rules tagged attack.t1190
157
KEV CVEs mapped here
<p>Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.</p><p>Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers. Depending on the flaw being exploited, this may also involve Exploitation for Stealth or Exploitation for Client Execution.</p><p>If an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the Cloud Instance Metadata API), exploit container host access via Escape to Host, or take advantage of weak identity and access management policies.</p><p>Adversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses.</p><p>For websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-49704 | Microsoft SharePoint | exploitation technique | Mapped | 2025-07-22 |
| CVE-2025-49706 | Microsoft SharePoint | exploitation technique | Mapped | 2025-07-22 |
| CVE-2025-53770 | Microsoft SharePoint | exploitation technique | Mapped | 2025-07-20 |
| CVE-2025-25257 | Fortinet FortiWeb | exploitation technique | Mapped | 2025-07-18 |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway | exploitation technique | Mapped | 2025-07-10 |
| CVE-2016-10033 | PHP PHPMailer | exploitation technique | Mapped | 2025-07-07 |
| CVE-2024-0769 | D-Link DIR-859 Router | exploitation technique | Mapped | 2025-06-25 |
| CVE-2025-35939 | Craft CMS Craft CMS | exploitation technique | Mapped | 2025-06-02 |
| CVE-2023-38950 | ZKTeco BioTime | exploitation technique | Mapped | 2025-05-19 |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) | exploitation technique | Mapped | 2025-05-19 |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | exploitation technique | Mapped | 2025-05-19 |
| CVE-2025-42999 | SAP NetWeaver | exploitation technique | Mapped | 2025-05-15 |
| CVE-2025-34028 | Commvault Command Center | exploitation technique | Mapped | 2025-05-02 |
| CVE-2024-38475 | Apache HTTP Server | exploitation technique | Mapped | 2025-05-01 |
| CVE-2025-42599 | Qualitia Active! Mail | exploitation technique | Mapped | 2025-04-28 |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | exploitation technique | Mapped | 2025-04-04 |
| CVE-2017-12637 | SAP NetWeaver | exploitation technique | Mapped | 2025-03-19 |
| CVE-2024-48248 | NAKIVO Backup and Replication | exploitation technique | Mapped | 2025-03-19 |
| CVE-2025-1316 | Edimax IC-7100 IP Camera | exploitation technique | Mapped | 2025-03-19 |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | exploitation technique | Mapped | 2025-03-10 |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | exploitation technique | Mapped | 2025-03-10 |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | exploitation technique | Mapped | 2025-03-10 |
| CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics (BA) Server | exploitation technique | Mapped | 2025-03-03 |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) | exploitation technique | Mapped | 2025-02-24 |
| CVE-2025-0108 | Palo Alto Networks PAN-OS | exploitation technique | Mapped | 2025-02-18 |
| CVE-2024-57727 | SimpleHelp SimpleHelp | exploitation technique | Mapped | 2025-02-13 |
| CVE-2025-23006 | SonicWall SMA1000 Appliances | exploitation technique | Mapped | 2025-01-24 |
| CVE-2023-48365 | Qlik Sense | exploitation technique | Mapped | 2025-01-13 |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | exploitation technique | Mapped | 2025-01-08 |
| CVE-2024-55550 | Mitel MiCollab | exploitation technique | Mapped | 2025-01-07 |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | primary impact | Mapped | 2024-07-29 |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | exploitation technique | Mapped | 2024-07-17 |
| CVE-2024-4358 | Progress Telerik Report Server | exploitation technique | Mapped | 2024-06-13 |
| CVE-2024-4577 | PHP Group PHP | exploitation technique | Mapped | 2024-06-12 |
| CVE-2021-40655 | D-Link DIR-605 Router | exploitation technique | Mapped | 2024-05-16 |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | exploitation technique | Mapped | 2024-04-24 |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | exploitation technique | Mapped | 2024-03-25 |
| CVE-2023-48788 | Fortinet FortiClient EMS | exploitation technique | Mapped | 2024-03-25 |
| CVE-2024-27198 | JetBrains TeamCity | exploitation technique | Mapped | 2024-03-07 |
| CVE-2021-36380 | Sunhillo SureLine | exploitation technique | Mapped | 2024-03-05 |
| CVE-2024-21762 | Fortinet FortiOS | exploitation technique | Mapped | 2024-02-09 |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | exploitation technique | Mapped | 2024-01-31 |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | exploitation technique | Mapped | 2024-01-10 |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | exploitation technique | Mapped | 2024-01-10 |
| CVE-2023-27524 | Apache Superset | exploitation technique | Mapped | 2024-01-08 |
| CVE-2023-29300 | Adobe ColdFusion | exploitation technique | Mapped | 2024-01-08 |
| CVE-2023-38203 | Adobe ColdFusion | exploitation technique | Mapped | 2024-01-08 |
| CVE-2023-7101 | Spreadsheet::ParseExcel Spreadsheet::ParseExcel | exploitation technique | Mapped | 2024-01-02 |
| CVE-2023-49103 | ownCloud ownCloud graphapi | exploitation technique | Mapped | 2023-11-30 |
| CVE-2023-36844 | Juniper Junos OS | primary impact | Mapped | 2023-11-13 |
| CVE-2023-36845 | Juniper Junos OS | exploitation technique | Mapped | 2023-11-13 |
| CVE-2023-36846 | Juniper Junos OS | exploitation technique | Mapped | 2023-11-13 |
| CVE-2023-36847 | Juniper Junos OS | exploitation technique | Mapped | 2023-11-13 |
| CVE-2023-36851 | Juniper Junos OS | exploitation technique | Mapped | 2023-11-13 |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server | exploitation technique | Mapped | 2023-11-07 |
| CVE-2023-46604 | Apache ActiveMQ | exploitation technique | Mapped | 2023-11-02 |
| CVE-2023-20198 | Cisco IOS XE Web UI | exploitation technique | Mapped | 2023-10-16 |
| CVE-2023-44487 | IETF HTTP/2 | exploitation technique | Mapped | 2023-10-10 |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | exploitation technique | Mapped | 2023-10-05 |
| CVE-2023-42793 | JetBrains TeamCity | exploitation technique | Mapped | 2023-10-04 |
| CVE-2021-3129 | Laravel Ignition | exploitation technique | Mapped | 2023-09-18 |
| CVE-2023-33246 | Apache RocketMQ | exploitation technique | Mapped | 2023-09-06 |
| CVE-2023-38035 | Ivanti Sentry | exploitation technique | Mapped | 2023-08-22 |
| CVE-2023-26359 | Adobe ColdFusion | exploitation technique | Mapped | 2023-08-21 |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) | exploitation technique | Mapped | 2023-07-31 |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | exploitation technique | Mapped | 2023-07-25 |
| CVE-2023-29298 | Adobe ColdFusion | exploitation technique | Mapped | 2023-07-20 |
| CVE-2023-38205 | Adobe ColdFusion | exploitation technique | Mapped | 2023-07-20 |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | exploitation technique | Mapped | 2023-07-19 |
| CVE-2023-20887 | VMware Aria Operations for Networks | exploitation technique | Mapped | 2023-06-22 |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | exploitation technique | Mapped | 2023-06-13 |
| CVE-2023-34362 | Progress MOVEit Transfer | exploitation technique | Mapped | 2023-06-02 |
| CVE-2023-27350 | PaperCut MF/NG | exploitation technique | Mapped | 2023-04-21 |
| CVE-2023-29492 | Novi Survey Novi Survey | exploitation technique | Mapped | 2023-04-13 |
| CVE-2022-42948 | Fortra Cobalt Strike | exploitation technique | Mapped | 2023-03-30 |
| CVE-2022-39197 | Fortra Cobalt Strike | exploitation technique | Mapped | 2023-03-30 |
| CVE-2023-26360 | Adobe ColdFusion | exploitation technique | Mapped | 2023-03-15 |
| CVE-2021-39144 | XStream XStream | exploitation technique | Mapped | 2023-03-10 |
| CVE-2022-28810 | Zoho ManageEngine | exploitation technique | Mapped | 2023-03-07 |
| CVE-2022-35914 | Teclib GLPI | exploitation technique | Mapped | 2023-03-07 |
| CVE-2023-0669 | Fortra GoAnywhere MFT | exploitation technique | Mapped | 2023-02-10 |
| CVE-2023-22952 | SugarCRM Multiple Products | exploitation technique | Stale | 2023-02-02 |
| CVE-2022-47966 | Zoho ManageEngine | exploitation technique | Mapped | 2023-01-23 |
| CVE-2022-42475 | Fortinet FortiOS | exploitation technique | Mapped | 2022-12-13 |
| CVE-2022-26500 | Veeam Backup & Replication | exploitation technique | Mapped | 2022-12-13 |
| CVE-2022-26501 | Veeam Backup & Replication | exploitation technique | Mapped | 2022-12-13 |
| CVE-2022-40684 | Fortinet Multiple Products | exploitation technique | Mapped | 2022-10-11 |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center | exploitation technique | Mapped | 2022-09-30 |
| CVE-2022-26258 | D-Link DIR-820L | exploitation technique | Mapped | 2022-09-08 |
| CVE-2022-22963 | VMware Tanzu Spring Cloud | exploitation technique | Mapped | 2022-08-25 |
| CVE-2021-39226 | Grafana Labs Grafana | exploitation technique | Mapped | 2022-08-25 |
| CVE-2022-0028 | Palo Alto Networks PAN-OS | exploitation technique | Mapped | 2022-08-22 |
| CVE-2022-26134 | Atlassian Confluence Server/Data Center | exploitation technique | Mapped | 2022-06-02 |
| CVE-2022-20821 | Cisco IOS XR | exploitation technique | Mapped | 2022-05-23 |
| CVE-2022-22947 | VMware Spring Cloud Gateway | exploitation technique | Mapped | 2022-05-16 |
| CVE-2022-29464 | WSO2 Multiple Products | exploitation technique | Mapped | 2022-04-25 |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack | exploitation technique | Mapped | 2022-04-06 |
| CVE-2022-22965 | VMware Spring Framework | exploitation technique | Mapped | 2022-04-04 |
| CVE-2021-45382 | D-Link Multiple Routers | exploitation technique | Mapped | 2022-04-04 |
| CVE-2022-1040 | Sophos Firewall | exploitation technique | Mapped | 2022-03-31 |
| CVE-2021-26085 | Atlassian Confluence Server | exploitation technique | Mapped | 2022-03-28 |
| CVE-2010-2861 | Adobe ColdFusion | exploitation technique | Mapped | 2022-03-25 |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation | exploitation technique | Mapped | 2022-03-07 |
| CVE-2013-0631 | Adobe ColdFusion | exploitation technique | Mapped | 2022-03-07 |
| CVE-2013-0629 | Adobe ColdFusion | exploitation technique | Mapped | 2022-03-07 |
| CVE-2013-0625 | Adobe ColdFusion | exploitation technique | Mapped | 2022-03-07 |
| CVE-2009-3960 | Adobe BlazeDS | exploitation technique | Mapped | 2022-03-07 |
| CVE-2022-20708 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | exploitation technique | Mapped | 2022-03-03 |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | exploitation technique | Mapped | 2022-03-03 |
| CVE-2013-0632 | Adobe ColdFusion | exploitation technique | Mapped | 2022-03-03 |
| CVE-2022-23131 | Zabbix Frontend | exploitation technique | Mapped | 2022-02-22 |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | exploitation technique | Mapped | 2022-02-15 |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | exploitation technique | Mapped | 2022-01-28 |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | exploitation technique | Mapped | 2022-01-28 |
| CVE-2021-21975 | VMware vRealize Operations Manager API | exploitation technique | Mapped | 2022-01-18 |
| CVE-2021-22017 | VMware vCenter Server | exploitation technique | Mapped | 2022-01-10 |
| CVE-2021-27860 | FatPipe WARP, IPVPN, and MPVPN software | exploitation technique | Mapped | 2022-01-10 |
| CVE-2021-44515 | Zoho Desktop Central | exploitation technique | Mapped | 2021-12-10 |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | exploitation technique | Mapped | 2021-12-10 |
| CVE-2021-44228 | Apache Log4j2 | exploitation technique | Mapped | 2021-12-10 |
| CVE-2021-37415 | Zoho ManageEngine ServiceDesk Plus (SDP) | exploitation technique | Mapped | 2021-12-01 |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | exploitation technique | Mapped | 2021-12-01 |
| CVE-2021-22204 | Perl Exiftool | exploitation technique | Mapped | 2021-11-17 |
| CVE-2021-27104 | Accellion FTA | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-27102 | Accellion FTA | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-27103 | Accellion FTA | exploitation technique | Mapped | 2021-11-03 |
| CVE-2018-4939 | Adobe ColdFusion | primary impact | Mapped | 2021-11-03 |
| CVE-2018-15961 | Adobe ColdFusion | exploitation technique | Mapped | 2021-11-03 |
| CVE-2017-9805 | Apache Struts | exploitation technique | Mapped | 2021-11-03 |
| CVE-2016-4437 | Apache Shiro | exploitation technique | Mapped | 2021-11-03 |
| CVE-2019-17558 | Apache Solr | exploitation technique | Mapped | 2021-11-03 |
| CVE-2020-17530 | Apache Struts | exploitation technique | Mapped | 2021-11-03 |
| CVE-2017-5638 | Apache Struts | exploitation technique | Mapped | 2021-11-03 |
| CVE-2018-11776 | Apache Struts | exploitation technique | Mapped | 2021-11-03 |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | exploitation technique | Mapped | 2021-11-03 |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | exploitation technique | Mapped | 2021-11-03 |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices | exploitation technique | Mapped | 2021-11-03 |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | exploitation technique | Mapped | 2021-11-03 |
| CVE-2018-7600 | Drupal Drupal Core | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | exploitation technique | Mapped | 2021-11-03 |
| CVE-2018-6789 | Exim Exim | exploitation technique | Mapped | 2021-11-03 |
| CVE-2020-5902 | F5 BIG-IP | exploitation technique | Stale | 2021-11-03 |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-35464 | ForgeRock Access Management (AM) | exploitation technique | Mapped | 2021-11-03 |
| CVE-2018-13379 | Fortinet FortiOS | exploitation technique | Mapped | 2021-11-03 |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-34523 | Microsoft Exchange Server | exploitation technique | Mapped | 2021-11-03 |
| CVE-2020-0688 | Microsoft Exchange Server | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-34473 | Microsoft Exchange Server | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-26858 | Microsoft Exchange Server | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-27065 | Microsoft Exchange Server | exploitation technique | Mapped | 2021-11-03 |
| CVE-2019-0604 | Microsoft SharePoint | exploitation technique | Mapped | 2021-11-03 |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-22005 | VMware vCenter Server | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-21972 | VMware vCenter Server | exploitation technique | Mapped | 2021-11-03 |
| CVE-2021-40539 | Zoho ManageEngine | exploitation technique | Mapped | 2021-11-03 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0080 Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress) v1.0
AN0219 WindowsAdversary sends crafted HTTP/S (or other service) input to an Internet-facing app (IIS/ASP.NET, API, device portal). Chain: (1) abnormal request patterns to public endpoint → (2) elevated 4xx/5xx or unusual methods/paths → (3) server process (w3wp.exe/other service) spawns shell/LOLbins or loads non-standard modules → (4) optional outbound callback from the host/container.ApplicationLog:IIS
IIS W3C logs in C:\inetpub\logs\LogFiles\W3SVC* (spikes in 5xx, RCE/SQLi/path traversal/JNDI patterns)→ DC0038 Application Log ContentTunable:PublicVIPsSuspiciousPatternsErrorRateThresholdTimeWindowAllowedChildListAN0220 LinuxAdversary exploits Apache/Nginx/app servers. Chain: (1) suspicious requests in access logs → (2) spike of 5xx or WAF blocks → (3) web server or interpreter (apache2/nginx/php-fpm/node/python) spawns /bin/sh, curl, wget, socat, or writes webshell → (4) outbound callback.ApplicationLog:WebServer/var/log/httpd/access_log, /var/log/apache2/access.log, /var/log/nginx/access.log with exploit indicators and burst errors→ DC0038 Application Log ContentNSM:FlowHTTP payloads with SQLi/LFI/JNDI/deserialization indicators→ DC0085 Network Traffic ContentTunable:WebProcListChildToolListBurstThresholdTimeWindowAN0221 macOSAdversary targets macOS-hosted public services (e.g., nginx, node). Chain: suspicious inbound request → service crash/5xx → service spawns shell or writes file → new outbound connection.macos:unifiedlogApp/web server logs ingested via unified logging or filebeat (nginx/apache/node).→ DC0038 Application Log ContentTunable:ServiceListTimeWindowAN0222 ContainersAdversary exploits containerized app via ingress or service. Chain: (1) suspicious request in ingress/app logs → (2) container process spawns a shell/exec/sidecar (kubectl exec/docker exec) → (3) egress to Internet or metadata service (169.254.169.254).ApplicationLog:IngressKubernetes NGINX/Envoy ingress controller logs with anomalous payloads and 5xx spikes→ DC0038 Application Log Contentdocker:eventsDocker/Kubernetes audit of exec/attach (kubectl exec) or unexpected child processes inside container→ DC0032 Process CreationNSM:FlowRequests towards cloud metadata or command & control from pod IPs→ DC0085 Network Traffic ContentTunable:IngressNamespacesMetadataEndpointsTimeWindowAN0223 IaaSAdversary targets cloud-hosted public endpoints. Chain: (1) ALB/ELB/Cloud LB logs show exploit-like inputs or error spikes → (2) workload spawns shell or reaches metadata API → (3) egress to new external hosts.ALB:HTTPLogsAWS ALB/ELB/GCP/Azure Application Gateway HTTP logs with unusual methods, long URIs, serialized payloads, 4xx/5xx bursts→ DC0085 Network Traffic ContentAWS:VPCFlowLogsVPC/NSG flow logs for pod/instance egress to Internet or metadata→ DC0078 Network Traffic FlowTunable:LBProjectsErrorBurstAN0224 ESXiAdversary exploits exposed OpenSLP on ESXi or vCenter public endpoints. Chain: inbound request pattern to mgmt service → hostd/vpxd error/crash/restart → unexpected process behavior or datastore access → outbound callback.esxi:hostd/var/log/hostd.log anomalies (faults, crashes, restarts) around inbound connections→ DC0038 Application Log ContentNSM:FlowConnections to TCP 427 (SLP) or vCenter web services from untrusted sources→ DC0085 Network Traffic ContentTunable:MgmtCIDRTimeWindowAN0225 Network DevicesAdversary exploits public admin services on routers/firewalls/switches. Chain: anomalous HTTP/SNMP/SmartInstall inputs → device syslog errors/restarts → config changes/CLI spawn → egress to attacker C2.networkdevice:controlplaneSyslog from edge devices with HTTP 500s on mgmt portal, SmartInstall events, unexpected CLI commands→ DC0038 Application Log ContentTunable:MgmtPortsTrustedAdmins
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1190
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-05-30 · logsource: category=webserver · 043c1609-0e32-4462-a6f2-5a0c2da3fafe
Detects a potential exploitation attempt of CVE-2023-25717 a Remote Code Execution via an unauthenticated HTTP GET Request, in Ruckus Wireless Admin
Author: @gott_cyber
· 2022-12-11 (modified 2023-03-24) · logsource: category=webserver · 0bbcd74b-0596-41a4-94a0-4e88a76ffdb3
Detects exploitation attempt of the CVE-2021-27905 which affects all Apache Solr versions prior to and including 8.8.1.
Author: Florian Roth (Nextron Systems)
· 2020-07-10 (modified 2023-01-02) · logsource: category=webserver · 0d0d9a8a-a49e-4e27-b061-7ce4b936cfb7
Detects exploitation attempt against Citrix Netscaler, Application Delivery Controller (ADS) and Citrix Gateway exploiting vulnerabilities reported as CVE-2020-8193 and CVE-2020-8195
Author: Thomas Patzke
· 2017-08-06 (modified 2020-09-01) · logsource: product=ruby_on_rails category=application · 0d2c3d4c-4b48-4ac3-8f23-ea845746bb1a
Detects suspicious Ruby on Rails exceptions that could indicate exploitation attempts
Author: Bhabesh Raj
· 2023-02-23 · logsource: category=webserver · 0e1ebc5a-15d0-4bf6-8199-b2535397433a
Detects the potential exploitation attempt of CVE-2023-23752 an Improper access check, in web service endpoints in Joomla
Author: Nisarg Suthar
· 2025-08-01 · logsource: product=windows category=process_creation · 0fdc7c7f-c690-4217-9ae3-31f5156eed72
Detects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.
Author: Florian Roth (Nextron Systems)
· 2019-05-22 (modified 2023-01-25) · logsource: product=windows category=process_creation · 1012f107-b8f1-4271-af30-5aed2de89b39
Detects a process spawned by the terminal service server process (this could be an indicator for an exploitation of CVE-2019-0708)
Author: jamesc-grafana
· 2024-07-11 · logsource: product=aws service=cloudtrail · 14f3f1c8-02d5-43a2-a191-91ffb52d3015
Detects changes to the security group entries for RDS databases.
This can indicate that a misconfiguration has occurred which potentially exposes the database to the public internet, a wider audience within the VPC or that removal of valid rules has occurred which could impact the availability of the database to legitimate services and users.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-11-20 · logsource: category=proxy · 15697955-6a29-47ca-92e9-0e05efae3260
Detects suspicious requests to Cisco ASA WebVpn via proxy logs associated with CVE-2025-20333 and CVE-2025-20362 exploitation.
Author: Bhabesh Raj
· 2021-01-25 (modified 2023-01-02) · logsource: category=webserver · 15c312b9-00d0-4feb-8870-7d940a4bdc5e
Detects the exploitation of the TerraMaster TOS vulnerability described in CVE-2020-28188
Author: Moti Harmats
· 2023-02-11 · logsource: product=velocity category=application · 16c86189-b556-4ee8-b4c7-7e350a195a4f
Detects exceptions in velocity template renderer, this most likely happens due to dynamic rendering of user input and may lead to RCE.
Author: Bhabesh Raj
· 2021-02-24 (modified 2023-01-02) · logsource: category=webserver · 179ed852-0f9b-4009-93a7-68475910fd86
Detects the exploitation of VSphere Remote Code Execution vulnerability as described in CVE-2021-21972
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-12-22 (modified 2023-01-02) · logsource: category=webserver · 181f49fa-0b21-4665-a98c-a57025ebb8c7
Detects exploitation attempt of the OWASSRF variant targeting exchange servers It uses the OWA endpoint to access the powershell backend endpoint
Author: Nasreddine Bencherchali (Nextron Systems), Tim Shelton
· 2022-07-19 (modified 2026-06-11) · logsource: category=webserver · 19aa4f58-94ca-45ff-bc34-92e533c0994a
Detects known suspicious (default) user-agents related to scanning/recon tools
Author: Thomas Patzke
· 2017-08-12 (modified 2020-09-01) · logsource: product=python category=application · 19aefed0-ffd4-47dc-a7fc-f8b1425e84f9
Generic rule for SQL exceptions in Python according to PEP 249
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-07-19 (modified 2023-01-02) · logsource: category=webserver · 1a9a04fd-02d1-465c-abad-d733fd409f9c
Detects attempts to exploit an apache spark server via CVE-2014-6287 from a weblogs perspective
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-20 · logsource: category=webserver · 1b2eeb27-949b-4704-8bfa-d8e5cfa045a1
Detects potential exploitation attempts that target the Centos Web Panel 7 Unauthenticated Remote Code Execution CVE-2022-44877
Author: Andreas Braathen (mnemonic.io)
· 2023-11-14 · logsource: product=windows category=process_creation · 1ddaa9a4-eb0b-4398-a9fe-7b018f9e23db
Detects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-12-22 · logsource: category=proxy · 1ddf4596-1908-43c9-add2-1d2c2fcc4797
Detects exploitation attempt of the OWASSRF variant targeting exchange servers It uses the OWA endpoint to access the powershell backend endpoint
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-07-24 · logsource: product=windows category=file_event · 1f0489be-b496-4ddf-b3a9-5900f2044e9c
Detects suspicious file writes to SharePoint layouts directory which could indicate webshell activity or post-exploitation.
This behavior has been observed in the exploitation of SharePoint vulnerabilities such as CVE-2025-49704, CVE-2025-49706 or CVE-2025-53770.
Author: Florian Roth (Nextron Systems)
· 2021-11-17 (modified 2023-01-02) · logsource: category=webserver · 20c6ed1c-f7f0-4ea3-aa65-4f198e6acb0f
Detects exploitation attempts of Sitecore Experience Platform Pre-Auth RCE CVE-2021-42237 found in Report.ashx
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
· 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 21541900-27a9-4454-9c4c-3f0a4240344a
Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell.
SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including
Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Author: Florian Roth (Nextron Systems), Rich Warren
· 2021-08-07 (modified 2023-01-02) · logsource: category=webserver · 23eee45e-933b-49f9-ae1b-df706d2d52ef
Detects URL patterns that could be found in ProxyShell exploitation attempts against Exchange servers (failed and successful)
Author: Bhabesh Raj
· 2021-09-08 (modified 2023-02-13) · logsource: product=windows category=process_creation · 245f92e3-c4da-45f1-9070-bc552e06db11
Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084
Author: Swachchhanda Shrawan Poudel (Nextron Systems), Nasreddine Bencherchali
· 2025-12-05 · logsource: product=windows category=process_creation · 271de298-cc0e-4842-acd8-079a0a99ea65
Detects suspicious child processes started by Node.js server processes on Windows, which may indicate exploitation of vulnerabilities like CVE-2025-55182 (React2Shell).
Attackers can abuse the Node.js 'child_process' module to run system commands or scripts using methods such as spawn(), exec(), execFile(), fork(), or execSync().
If execSync() or exec() is used in the exploit, the command line often shows a shell (e.g., cmd.exe /d /s /c ...) running a suspicious command unless other shells are explicitly invoked.
For other methods, the spawned process appears directly in the Image field unless a shell is explicitly used.
Author: Andreas Braathen (mnemonic.io)
· 2023-11-14 · logsource: category=proxy · 27d2cdde-9778-490e-91ec-9bd0be6e8cc6
Detects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
Author: Florian Roth (Nextron Systems)
· 2019-11-18 (modified 2023-01-02) · logsource: category=webserver · 2dbc10d7-a797-49a8-8776-49efa6442e60
Detects CVE-2019-11510 exploitation attempt - URI contains Guacamole
Author: daffainfo, Florian Roth
· 2021-10-05 (modified 2023-01-02) · logsource: category=webserver · 3007fec6-e761-4319-91af-e32e20ac43f5
Detects exploitation of flaw in path normalization in Apache HTTP server 2.4.49.
An attacker could use a path traversal attack to map URLs to files outside the expected document root.
If files outside of the document root are not protected by "require all denied" these requests can succeed.
Additionally this flaw could leak the source of interpreted files like CGI scripts.
This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions.
Author: Sergio Palacios Dominguez, Nasreddine Bencherchali (Nextron Systems)
· 2023-07-28 · logsource: category=webserver · 31e4e649-7394-4fd2-9ae7-dbc61eebb550
Detects indicators of potential exploitation of CVE-2023-27997 in Frotigate weblogs.
To avoid false positives it is best to look for successive requests to the endpoints mentioned as well as weird values of the "enc" parameter
Author: Florian Roth (Nextron Systems)
· 2017-07-05 (modified 2021-11-27) · logsource: product=linux service=vsftpd · 377f33a1-4b36-4ee1-acee-1dbe4b43cfbe
Detects suspicious VSFTPD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
Author: Florian Roth (Nextron Systems)
· 2018-07-22 (modified 2023-01-02) · logsource: category=webserver · 37e8369b-43bb-4bf8-83b6-6dd43bda2000
Detects access to a webshell dropped into a keystore folder on the WebLogic server
Author: Sittikorn S, Nuttakorn T
· 2022-12-13 (modified 2023-03-24) · logsource: category=webserver · 38825179-3c78-4fed-b222-2e2166b926b1
Detects potential exploitation of CVE-2021-260841 a Confluence RCE using OGNL injection
Author: @kostastsale
· 2022-01-14 · logsource: product=windows category=process_creation · 3eb91f0a-0060-424a-a676-59f5fdd75610
Detects potential initial exploitation attempts against VMware Horizon deployments running a vulnerable versions of Log4j.
Author: Florian Roth (Nextron Systems)
· 2021-12-12 (modified 2022-12-25) · logsource: category=webserver · 412d55bc-7737-4d25-9542-5b396867ce55
Detects exploitation attempt using the JNDI-Exploit-Kit
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-05-20 · logsource: category=webserver · 41956f7c-7a6b-46d6-b6bb-da6eb2e83fbe
Detects potential exploitation of a chained vulnerability attack targeting Ivanti EPMM 12.5.0.0.
CVE-2025-4427 allows unauthenticated access to protected API endpoints via an authentication bypass,
which can then be leveraged to trigger CVE-2025-4428 — a remote code execution vulnerability through
template injection. This sequence enables unauthenticated remote code execution, significantly increasing
the impact of exploitation.
Author: Huntress Labs, Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-10-31 · logsource: product=windows category=process_creation · 43259cc4-1b80-4931-bd98-baea01afc196
Detects the creation of command-line interpreters (cmd.exe, powershell.exe) as child processes of Windows Server Update Services (WSUS) related process wsusservice.exe.
This behavior is a key indicator of exploitation for the critical remote code execution vulnerability such as CVE-2025-59287, where attackers spawn shells to conduct reconnaissance and further post-exploitation activities.
Author: Florian Roth (Nextron Systems)
· 2020-07-05 (modified 2023-01-02) · logsource: category=webserver · 44b53b1c-e60f-4a7b-948e-3435a7918478
Detects the exploitation attempt of the vulnerability found in F5 BIG-IP and described in CVE-2020-5902
Author: Craig Sweeney, Matt Anderson, Jose Oregon, Tim Kasper, Faith Stratton, Samantha Shaw, Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-04-10 · logsource: product=windows category=process_creation · 459628e3-1b00-4e9b-9e5b-7da8961aea35
Detects suspicious child processes spawned by the CrushFTP service that may indicate exploitation of remote code execution vulnerabilities such as
CVE-2025-31161, where attackers can achieve RCE through crafted HTTP requests.
The detection focuses on commonly abused Windows executables (like powershell.exe, cmd.exe etc.) that attackers typically use post-exploitation to execute malicious commands.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-07-21 · logsource: category=webserver · 48d053db-6a56-4866-b60d-0975647050ed
Detects access to vulnerable SharePoint components potentially being exploited in CVE-2025-53770 through IIS web server logs.
CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
Author: Moti Harmats
· 2023-02-11 · logsource: product=jvm category=application · 4d0af518-828e-4a04-a751-a7d03f3046ad
Detects potential OGNL Injection exploitation, which may lead to RCE.
OGNL is an expression language that is supported in many JVM based systems.
OGNL Injection is the reason for some high profile RCE's such as Apache Struts (CVE-2017-5638) and Confluence (CVE-2022-26134)
Author: Saw Win Naung, Nasreddine Bencherchali (Nextron Systems), Thurein Oo (Yoma Bank)
· 2020-02-22 (modified 2023-09-04) · logsource: category=webserver · 5513deaf-f49a-46c2-a6c8-3f111b5cb453
Detects potential SQL injection attempts via GET requests in access logs.
Author: Sittikorn S
· 2021-06-29 (modified 2023-01-02) · logsource: category=webserver · 5525edac-f599-4bfd-b926-3fa69860e766
This rule detects exploitation attempts using Pulse Connect Secure(PCS) vulnerability (CVE-2021-22893)
Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution
mediumtest
Author: @kostastsale
· 2022-04-25 · logsource: product=windows category=process_creation · 5660d8db-6e25-411f-b92f-094420168a5d
Detects potential exploitation attempt of CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access and Identity Manager.
As reported by Morphisec, part of the attack chain, threat actors used PowerShell commands that executed as a child processes of the legitimate Tomcat "prunsrv.exe" process application.
Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Christian Burkard (Nextron Systems)
· 2021-08-30 (modified 2023-01-02) · logsource: category=webserver · 56973b50-3382-4b56-bdf5-f51a3183797a
Detects the exploitation of Microsoft Exchange ProxyToken vulnerability as described in CVE-2021-33766
Author: frack113, Harjot Singh, "@cyb3rjy0t" (update)
· 2022-06-04 (modified 2023-01-19) · logsource: category=webserver · 583aa0a2-30b1-4d62-8bf3-ab73689efe6c
Detects possible Java payloads in web access logs
Author: Bhabesh Raj, Tim Shelton
· 2020-12-27 (modified 2023-01-02) · logsource: category=webserver · 5a35116f-43bc-4901-b62d-ef131f42a9af
Detects CVE-2020-10148 SolarWinds Orion API authentication bypass attempts
Author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-04-28 · logsource: product=windows category=process_creation · 5b304bcb-ac33-49d0-87af-fa1b3ca94333
Detects suspicious child processes spawned by SAP NetWeaver that could indicate potential
exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
Author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-04-28 · logsource: product=linux category=file_event · 5b91409c-cb18-4ab6-ac75-c5759f998409
Detects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories,
which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
Author: Andreas Hunkeler (@Karneades), Markus Neis
· 2021-05-20 (modified 2022-07-14) · logsource: product=windows category=process_creation · 5cc2cda8-f261-4d88-a2de-e9e193c86716
Detects suspicious processes including shells spawnd from WinRM host process
Author: Florian Roth (Nextron Systems)
· 2021-12-10 (modified 2022-02-06) · logsource: category=webserver · 5ea8faa8-db8b-45be-89b0-151b84c82702
Detects exploitation attempt against log4j RCE vulnerability reported as CVE-2021-44228 (Log4Shell)
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-09-29 (modified 2023-01-02) · logsource: category=webserver · 65c0a0ab-d675-4441-bd6b-d3db226a2685
Detects attempts to exploit the Atlassian Bitbucket Command Injection CVE-2022-36804
Author: Tobias Michalski (Nextron Systems), Max Altgelt (Nextron Systems)
· 2021-09-20 (modified 2023-01-02) · logsource: category=webserver · 6702b13c-e421-44cc-ab33-42cc25570f11
Detects suspicious access to URLs that was noticed in cases in which attackers exploitated the ADSelfService vulnerability CVE-2021-40539
Author: Florian Roth (Nextron Systems)
· 2021-03-03 (modified 2023-01-02) · logsource: category=webserver · 67bce556-312f-4c81-9162-c3c9ff2599b2
Detects exploitation attempts in Exchange server logs as described in blog posts reporting on HAFNIUM group activity
Author: Bhabesh Raj
· 2021-01-20 (modified 2023-01-02) · logsource: category=webserver · 687f6504-7f44-4549-91fc-f07bab065821
Detects the exploitation of the WebLogic server vulnerability described in CVE-2021-2109
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · 6991bc2b-ae2e-447f-bc55-3a1ba04c14e5
Detects instances where an FTP service on an OpenCanary node has had a login attempt.
Author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-04-28 · logsource: product=linux category=process_creation · 69dea60b-2deb-4c9e-a685-ad542f4367f9
Detects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential
exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
Author: Florian Roth (Nextron Systems)
· 2022-10-04 · logsource: product=windows category=file_event · 6b269392-9eba-40b5-acb6-55c882b20ba6
Detects suspicious file type dropped by an Exchange component in IIS
Author: MSFT (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-10-07 · logsource: product=windows category=process_creation · 6c76b3d0-afe4-4870-9443-ffe6773c5fef
Detects suspicious command execution by child processes of the GoAnywhere Managed File Transfer (MFT) application, which may indicate exploitation such as CVE-2025-10035.
This behavior is indicative of post-exploitation activity related to CVE-2025-10035, as observed in campaigns by the threat actor Storm-1175.
Author: Nasreddine Bencherchali (Nextron Systems), Rohit Jain
· 2024-06-25 · logsource: category=proxy · 6c7defa9-69f8-4c34-b815-41fce3931754
Detects potential exploitation attempt of CVE-2023-1389 an Unauthenticated Command Injection in TP-Link Archer AX21.
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali
· 2023-01-21 · logsource: product=windows category=process_creation · 6d5b8176-d87d-4402-8af4-53aee9db7b5d
Detects potential exploitation attempt of undocumented Windows Server Pre Auth Remote Code Execution (RCE)
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
· 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 6eea1bf6-f8d2-488a-a742-e6ef6c1b67db
Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell.
Script being executed gets created as a temp file in /tmp folder with a scx* prefix.
Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/.
The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including
Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Author: Florian Roth (Nextron Systems)
· 2021-01-25 (modified 2023-04-27) · logsource: category=webserver · 6f55f047-112b-4101-ad32-43913f52db46
Detects exploitation attempts of the SonicWall Jarrewrite Exploit
Author: jamesc-grafana
· 2024-07-11 · logsource: product=aws service=cloudtrail · 6fb77778-040f-4015-9440-572aa9b6b580
Detects when an account makes changes to the ingress or egress rules of a security group.
This can indicate that an attacker is attempting to open up new attack vectors in the account, that they are trying to exfiltrate data over the network, or that they are trying to allow machines in that VPC/Subnet to contact a C&C server.
Author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
· 2026-04-30 · logsource: category=webserver · 6fd25dd1-527b-47c8-baa4-2a0e77279c6f
Detects inbound web requests using the "libredtail-http" User-Agent.
libredtail-http is a unique User-Agent string associated with a campaign of automated, malicious scans and attacks targeting exposed container environments and web applications,notably identified in activities stemming from late 2024 through early 2026.
It is primarily used by the RedTail cryptominer malware to identify and exploit vulnerabilities for deploying cryptocurrency miners.
Author: Florian Roth (Nextron Systems)
· 2022-02-25 · logsource: product=windows category=file_event · 7280c9f3-a5af-45d0-916a-bc01cb4151c9
Detects suspicious activity in which the MSExchangeMailboxReplication process writes .asp and .apsx files to disk, which could be a sign of ProxyShell exploitation
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-12-27 (modified 2023-01-02) · logsource: category=webserver · 738cb115-881f-4df3-82cc-56ab02fc5192
Detects potential exploitation attempts that target the Cacti Command Injection CVE-2022-46169
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-07-21 · logsource: product=windows category=process_creation · 7477881c-ec3b-49d6-aced-7255944e5c59
Detects potential exploitation of CVE-2025-53770 by identifying indicators such as suspicious command lines discovered in Post-Exploitation activities.
CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
Author: Subhash Popuri (@pbssubhash), Florian Roth (Nextron Systems), Thurein Oo, Nasreddine Bencherchali (Nextron Systems)
· 2021-09-25 (modified 2023-08-31) · logsource: category=webserver · 7745c2ea-24a5-4290-b680-04359cb84b35
Detects path traversal exploitation attempts
Author: Bhabesh Raj
· 2020-03-10 (modified 2023-01-02) · logsource: category=webserver · 77586a7f-7ea4-4c41-b19c-820140b84ca9
Detects the exploitation of the VMware View Planner vulnerability described in CVE-2021-21978
Author: jamesc-grafana
· 2024-07-11 · logsource: product=aws service=cloudtrail · 7a4409fc-f8ca-45f6-8006-127d779eaad9
Detects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB).
This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.
Author: Florian Roth (Nextron Systems)
· 2021-12-08 (modified 2023-01-02) · logsource: category=webserver · 7b72b328-5708-414f-9a2a-6a6867c26e16
Detects a successful Grafana path traversal exploitation
Author: NVISO
· 2020-02-27 (modified 2023-01-02) · logsource: category=webserver · 7c64e577-d72e-4c3d-9d75-8de6d1f9146a
Detects CVE-2020-0688 Exploitation attempts
Author: frack113
· 2021-10-06 (modified 2023-01-02) · logsource: category=webserver · 7cb02516-6d95-4ffc-8eee-162075e111ac
When IIS uses an old .Net Framework it's possible to enumerate folders with the symbol "~"
Author: Florian Roth (Nextron Systems)
· 2021-11-22 (modified 2022-07-12) · logsource: product=windows service=application · 7dbb86de-a0cc-494c-8aa8-b2996c9ef3c8
Detects PoC tool used to exploit LPE vulnerability CVE-2021-41379
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-06-03 · logsource: product=linux category=process_creation · 7fb14105-530e-4e2e-8cfb-99f7d8700b66
Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2022-26134
Author: Thomas Patzke, Florian Roth (Nextron Systems), Zach Stanford @svch0st, Tim Shelton, Nasreddine Bencherchali (Nextron Systems)
· 2019-01-16 (modified 2024-11-26) · logsource: product=windows category=process_creation · 8202070f-edeb-4d31-a010-a26c72ac5600
Detects potentially suspicious processes being spawned by a web server process which could be the result of a successfully placed web shell or exploitation
Author: Florian Roth (Nextron Systems)
· 2020-03-25 (modified 2023-01-21) · logsource: product=windows category=process_creation · 846b866e-2a57-46ee-8e16-85fa92759be7
Detects the exploitation of Zoho ManageEngine Desktop Central Java Deserialization vulnerability reported as CVE-2020-10189
Author: Nasreddine Bencherchali (Nextron Systems), Thurein Oo
· 2023-11-08 · logsource: category=webserver · 85254a62-22be-4239-b79c-2ec17e566c37
Detects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which allows the execution of commands on the BIG-IP
Author: Florian Roth (Nextron Systems)
· 2020-11-02 (modified 2023-01-02) · logsource: category=webserver · 85d466b0-d74c-4514-84d3-2bdd3327588b
Detects exploitation attempts on WebLogic servers
Author: FPT.EagleEye Team, wagga
· 2020-12-11 (modified 2023-05-04) · logsource: product=windows category=process_creation · 869b9ca7-9ea2-4a5a-8325-e80e62f75445
Detects suspicious child processes of the SQLServer process. This could indicate potential RCE or SQL Injection.
Author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-04-28 · logsource: product=windows category=file_event · 86a7c91f-98c3-4f14-a58d-d989421e1234
Detects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories,
which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
Author: Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT)
· 2023-11-28 · logsource: category=webserver · 87c83d8e-5390-44ce-aa4a-d3b37e54d0a0
Detects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-10-20 · logsource: product=windows category=file_event · 89c42960-f244-4dad-9151-ae9b1a3287a2
Detects suspicious file writes to the root directory of web applications, particularly Apache web servers or Tomcat servers.
This may indicate an attempt to deploy malicious files such as web shells or other unauthorized scripts.
Author: Bjoern Kimminich
· 2017-11-27 (modified 2023-02-12) · logsource: product=sql category=application · 8a670c6d-7189-4b1c-8017-a417ca84a086
Detects SQL error messages that indicate probing for an injection attack
Author: Florian Roth (Nextron Systems)
· 2023-06-09 · logsource: product=linux service=sshd · 8b244735-5833-4517-a45b-28d8c63924c0
Detects potential exploitation attempt of CVE-2023-2283 an authentication bypass in libSSH. The exploitation method causes an error message stating that keys for curve25519 could not be generated. It is an error message that is a sign of an exploitation attempt. It is not a sign of a successful exploitation.
Author: Huntress Team, Swachchhanda Shrawan Poudel (Nextron Systems)
· 2026-02-11 · logsource: product=windows category=process_creation · 8c7f4a2d-3b9e-4f1c-9a6d-2e8f5c3d9a1b
Detects suspicious child processes spawned by SolarWinds WebHelpDesk (WHD) application, which may indicate exploitation activity leveraging RCE vulnerabilities such as CVE-2025-40551, CVE-2025-40536, or CVE-2025-26399
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-12-22 (modified 2023-01-02) · logsource: category=webserver · 92d78c63-5a5c-4c40-9b60-463810ffb082
Detects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-05-14 · logsource: category=webserver · 94e12f41-6cb3-45c5-97b1-c783a7bf2e72
Detects potential command execution via webshell in SAP NetViewer through JSP files with cmd parameter.
This rule is created to detect exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution via a webshell.
Author: Moti Harmats
· 2023-02-11 · logsource: product=nodejs category=application · 97661d9d-2beb-4630-b423-68985291a8af
Detects process execution related errors in NodeJS. If the exceptions are caused due to user input then they may suggest an RCE vulnerability.
Author: Florian Roth (Nextron Systems)
· 2021-12-10 (modified 2023-01-02) · logsource: category=webserver · 9be472ed-893c-4ec0-94da-312d2765f654
Detects exploitation attempt against log4j RCE vulnerability reported as CVE-2021-44228 in different header fields found in web server logs (Log4Shell)
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-07-19 (modified 2023-01-02) · logsource: category=webserver · a133193c-2daa-4a29-8022-018695fcf0ae
Detects attempts to exploit a Rejetto HTTP File Server (HFS) via CVE-2014-6287
Author: Florian Roth (Nextron Systems)
· 2021-05-14 (modified 2023-01-02) · logsource: category=webserver · a2a9d722-0acb-4096-bccc-daaf91a5037b
Detects successful exploitation of Exchange vulnerability as reported in CVE-2021-28480
Author: Nasreddine Bencherchali (Nextron Systems), Thurein Oo
· 2023-10-20 (modified 2023-10-30) · logsource: category=webserver · a2bcca38-9f3a-4d5e-b603-0c587e8569d7
Detects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in access logs.
Author: Bhabesh Raj
· 2020-12-08 (modified 2023-01-02) · logsource: category=webserver · a2e97350-4285-43f2-a63f-d0daff291738
Detects CVE-2018-13379 exploitation attempt against Fortinet SSL VPNs
Author: Subhash Popuri (@pbssubhash)
· 2021-08-25 (modified 2023-01-02) · logsource: category=webserver · a4a899e8-fd7a-49dd-b5a8-7044def72d61
MODx manager - Local File Inclusion:Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier,
when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter.
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
hightest
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-11-28 · logsource: category=webserver · a4e068b5-e27c-4f21-85b3-e69e5a4f7ce1
Detects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs by looking for a very long host header string.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2026-07-19 · logsource: category=webserver · a7c4e2f9-1b38-4d5c-9e72-3f4a5b6c7d8e
Detects the hardcoded "wp2shell" User-Agent string used by the wp2shell
PoC tool during all phases of CVE-2026-63030 and CVE-2026-60137 exploitation.
Author: Florian Roth (Nextron Systems)
· 2022-04-13 (modified 2023-02-03) · logsource: product=windows category=process_creation · a7cd7306-df8b-4398-b711-6f3e4935cf16
Detects suspicious remote procedure call (RPC) service anomalies based on the spawned sub processes (long shot to detect the exploitation of vulnerabilities like CVE-2022-26809)
Author: Andreas Braathen (mnemonic.io)
· 2023-11-14 · logsource: category=webserver · a902d249-9b9c-4dc4-8fd0-fbe528ef965c
Detects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
Author: Nate Guagenti (neu5ron)
· 2021-09-20 (modified 2025-11-03) · logsource: product=zeek service=http · ab6b1a39-a9ee-4ab4-b075-e83acf6e346b
Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request.
Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP).
Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
Author: Florian Roth (Nextron Systems)
· 2021-01-07 (modified 2023-01-02) · logsource: category=webserver · aba47adc-4847-4970-95c1-61dce62a8b29
Detects exploitation attempts on Cisco ASA FTD systems exploiting CVE-2020-3452 with a status code of 200 (sccessful exploitation)
Author: Arnim Rupp, Florian Roth
· 2020-01-02 (modified 2023-01-02) · logsource: category=webserver · ac5a6409-8c89-44c2-8d64-668c29a2d756
Detects CVE-2019-19781 exploitation attempt against Citrix Netscaler, Application Delivery Controller and Citrix Gateway Attack
Author: Thomas Patzke
· 2017-08-06 (modified 2020-09-01) · logsource: product=spring category=application · ae48ab93-45f7-4051-9dfe-5d30a3f78e33
Detects suspicious Spring framework exceptions that could indicate exploitation attempts
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-11-28 · logsource: category=proxy · aee7681f-b53d-4594-a9de-ac51e6ad3362
Detects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs by looking for a very long host header string.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · af1ac430-df6b-4b38-b976-0b52f07a0252
Detects instances where an HTTP service on an OpenCanary node has had login attempt via Form POST.
Author: Security Onion Solutions
· 2024-03-08 · logsource: product=opencanary category=application · af6c3078-84cd-4c68-8842-08b76bd81b13
Detects instances where an HTTP service on an OpenCanary node has received a GET request.
Author: Florian Roth (Nextron Systems), Matt Kelly (list of domains)
· 2022-06-07 (modified 2026-07-23) · logsource: category=dns · aff715fa-4dd5-497a-8db3-910bea555566
Detects DNS queries to well-known out-of-band application security testing (OAST) and callback domains.
These services (e.g. Burp Collaborator, interactsh, canarytokens, dnslog.cn) are used by security
researchers and attackers alike to confirm blind vulnerabilities such as SSRF, XXE, blind RCE, and
Log4Shell-style injections, where the exploit payload triggers an external DNS lookup to a controlled domain.
A detection indicates that a host on your network resolved one of these domains, which may mean:
(1) an attacker is actively probing or exploiting a vulnerable service and using the callback to
confirm code execution or data exfiltration,
(2) a security scanner (e.g. Nuclei, Gobies) is running against internal targets.
Investigate the source host, the full DNS query string (the unique subdomain prefix encodes the callback session),
and any concurrent outbound connections or process activity to determine intent.
Author: Sittikorn S
· 2021-09-24 (modified 2023-01-02) · logsource: category=webserver · b014ea07-8ea0-4859-b517-50a4e5b7ecec
Detects exploitation attempts using file upload vulnerability CVE-2021-22005 in the VMWare vCenter Server.
Author: Jason Rathbun (Blackpoint Cyber)
· 2024-02-26 · logsource: product=windows category=process_creation · b19146a3-25d4-41b4-928b-1e2a92641b1b
Detects potential web shell execution from the ScreenConnect server process.
Author: Florian Roth (Nextron Systems)
· 2020-07-15 (modified 2022-07-12) · logsource: product=windows category=process_creation · b5281f31-f9cc-4d0d-95d0-45b91c45b487
Detects exploitation of DNS RCE bug reported in CVE-2020-1350 by the detection of suspicious sub process
Author: Nasreddine Bencherchali (Nextron Systems), Thurein Oo
· 2023-11-08 · logsource: category=proxy · b59c98c6-95e8-4d65-93ee-f594dfb96b17
Detects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which allows the execution of commands on the BIG-IP
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2026-07-19 · logsource: category=webserver · b8d5f301-2c49-4e6d-af83-4a5b6c7d8e9f
Detects exploitation attempts against the WordPress REST batch endpoint (CVE-2026-63030,
CVE-2026-60137) using the wp2shell PoC tool. The tool sends POST requests to the batch endpoint
via the ?rest_route=/batch/v1 query parameter, covering all attack phases from initial probe
through SQL injection and pre-auth admin creation. A 207 response confirms the endpoint is
active on the target.
Author: Florian Roth (Nextron Systems)
· 2021-05-22 (modified 2023-01-02) · logsource: category=webserver · b9888738-29ed-4c54-96a4-f38c57b84bb3
Detects the exploitation of the Wazuh RCE vulnerability described in CVE-2021-26814
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-07-21 (modified 2025-07-24) · logsource: product=windows category=file_event · ba479447-721f-42a9-9af2-6dcd517bbdb3
Detects the creation of file such as spinstall0.aspx which may indicate successful exploitation of CVE-2025-53770.
CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
Author: Moti Harmats
· 2023-02-11 · logsource: product=jvm category=application · bb0e9cec-d4da-46f5-997f-22efc59f3dca
Detects potential JNDI Injection exploitation. Often coupled with Log4Shell exploitation.
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
· 2023-06-01 (modified 2024-08-13) · logsource: product=windows category=file_event · c3b2a774-3152-4989-83c1-7afc48fd1599
Detects file indicators of potential exploitation of MOVEit CVE-2023-34362.
Author: Florian Roth (Nextron Systems)
· 2017-07-08 (modified 2022-07-07) · logsource: category=proxy · c42a3073-30fb-48ae-8c99-c23ada84b103
Detects suspicious user agent strings user by hack tools in proxy logs
Author: Moti Harmats
· 2023-02-11 · logsource: product=jvm category=application · c4e06896-e27c-4583-95ac-91ce2279345d
Detects XML parsing issues, if the application expects to work with XML make sure that the parser is initialized safely.
Author: Swachchhanda Shrawan Poudel (Nextron Systems), Nasreddine Bencherchali
· 2025-12-05 · logsource: product=linux category=process_creation · c70834fa-fb9d-4aa0-9e7d-45ceed36f3f7
Detects suspicious child processes spawned from Node.js server processes on Linux systems, potentially indicating remote code execution exploitation such as CVE-2025-55182 (React2Shell).
This rule particularly looks for exploitation of vulnerability on Node.js Servers where attackers abuse Node.js child_process module to execute arbitrary system commands.
When execSync() or exec() is used, the command line often includes a shell invocation followed by suspicious commands or scripts (e.g., /bin/sh -c <malicious-command>).
For other methods, the Image field will show the spawned process directly.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-07-20 · logsource: product=linux category=process_creation · c8a5f584-cdc8-42cc-8cce-0398e4265de3
Detects attempts to exploit an apache spark server via CVE-2014-6287 from a commandline perspective
Author: Florian Roth (Nextron Systems)
· 2018-02-20 (modified 2022-10-05) · logsource: product=linux service=syslog · c8e35e96-19ce-4f16-aeb6-fd5588dc5365
Detects suspicious DNS error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
Author: Isa Almannaei
· 2023-02-13 · logsource: category=webserver · d033cb8a-8669-4a8e-a974-48d4185a8503
Detects potential exploitation attempts of CVE-2022-21587 an arbitrary file upload vulnerability impacting Oracle E-Business Suite (EBS). CVE-2022-21587 can lead to unauthenticated remote code execution.
Author: Florian Roth (Nextron Systems), wagga
· 2020-02-29 (modified 2022-12-25) · logsource: product=windows service=application · d6266bf5-935e-4661-b477-78772735a7cb
Detects the exploitation of Microsoft Exchange vulnerability as described in CVE-2020-0688
Author: Moti Harmats
· 2023-02-11 · logsource: product=jvm category=application · d65f37da-a26a-48f8-8159-3dde96680ad2
Detects process execution related exceptions in JVM based apps, often relates to RCE
Author: @juju4
· 2022-12-27 · logsource: category=database · d84c0ded-edd7-4123-80ed-348bb3ccc4d5
Detects suspicious SQL query keywrods that are often used during recon, exfiltration or destructive activities. Such as dropping tables and selecting wildcard fields
Author: @gott_cyber
· 2022-08-17 (modified 2023-01-02) · logsource: category=webserver · dd218fb6-4d02-42dc-85f0-a0a376072efd
Detects an attempt to leverage the vulnerable servlet "mboximport" for an unauthenticated remote command injection
Author: Moti Harmats
· 2023-02-11 · logsource: product=jvm category=application · e032f5bc-4563-4096-ae3b-064bab588685
Detects potential local file read vulnerability in JVM based apps.
If the exceptions are caused due to user input and contain path traversal payloads then it's a red flag.
Author: Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-10-31 · logsource: product=windows service=application · e5f66e87-7d6b-404f-92fe-7aa67814b5cd
Detects cast exceptions in Windows Server Update Services (WSUS) application logs that highly indicate exploitation attempts of CVE-2025-59287, a deserialization vulnerability in WSUS.
Author: Florian Roth (Nextron Systems)
· 2017-06-30 (modified 2021-11-27) · logsource: product=linux service=sshd · e76b413a-83d0-4b94-8e4c-85db4a5b8bdc
Detects suspicious SSH / SSHD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-11-08 · logsource: category=webserver · e9928831-ba14-42ea-a4bc-33d352b9929a
Detects exploitation activity of CVE-2023-46747 an unauthenticated remote code execution vulnerability in F5 BIG-IP.
Author: Florian Roth (Nextron Systems)
· 2019-01-22 (modified 2021-11-27) · logsource: service=apache · e9a2b582-3f6a-48ac-b4a1-6849cdc50b3c
Detects an issue in apache logs that reports threading related errors
Author: Florian Roth (Nextron Systems)
· 2020-05-26 (modified 2023-01-02) · logsource: category=webserver · e9bc39ae-978a-4e49-91ab-5bd481fc668b
Detects the exploitation of the Confluence vulnerability described in CVE-2019-3398
Author: Moti Harmats
· 2023-02-11 · logsource: product=spring category=application · e9edd087-89d8-48c9-b0b4-5b9bb10896b8
Detects potential SpEL Injection exploitation, which may lead to RCE.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-08-12 (modified 2023-01-02) · logsource: category=webserver · efdb2003-a922-48aa-8f37-8b80021a9706
Detects possible exploitation of VMware Workspace ONE Access Admin Remote Code Execution vulnerability as described in CVE-2022-31659
Author: frack113
· 2021-08-10 (modified 2023-05-08) · logsource: category=webserver · effee1f6-a932-4297-a81f-acb44064fa3a
When exploiting this vulnerability with CVE-2021-26858, an SSRF attack is used to manipulate virtual directories
Author: Tanner Filip, Austin Worline, Chad Hudson, Matt Anderson
· 2024-12-09 · logsource: product=windows category=process_creation · f007b877-02e3-45b7-8501-1b78c2864029
Detects exploitation attempt of Cleo's CVE-2024-50623 by looking for a "cmd.exe" process spawning from the Celo software suite with suspicious Powershell commandline.
Author: Bhabesh Raj
· 2021-08-24 (modified 2023-01-02) · logsource: category=webserver · f0500377-bc70-425d-ac8c-e956cd906871
Detects exploitation of vulnerabilities in Arcadyan routers as reported in CVE-2021-20090 and CVE-2021-20091.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-11-08 · logsource: category=proxy · f195b2ff-e542-41bf-8d91-864fb81e5c20
Detects exploitation activity of CVE-2023-46747 an unauthenticated remote code execution vulnerability in F5 BIG-IP.
Author: Bhabesh Raj, Florian Roth
· 2021-08-19 (modified 2023-01-02) · logsource: category=webserver · f425637f-891c-4191-a6c4-3bb1b70513b4
Detects CVE-2021-22123 exploitation attempt against Fortinet WAFs
Author: Nasreddine Bencherchali (Nextron Systems), Thurein Oo
· 2023-10-20 (modified 2023-10-30) · logsource: category=proxy · f48f5368-355c-4a1b-8bf5-11c13d589eaa
Detects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in proxy logs.
Author: NVISO
· 2020-05-06 (modified 2024-03-11) · logsource: product=windows service=security · f88e112a-21aa-44bd-9b01-6ee2a2bbbed1
Detects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.
Author: Andreas Braathen (mnemonic.io)
· 2023-11-14 · logsource: product=linux category=process_creation · f8987c03-4290-4c96-870f-55e75ee377f4
Detects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
Author: Sittikorn S, Nuttakorn Tungpoonsup
· 2021-09-10 (modified 2023-01-02) · logsource: category=webserver · fcbb4a77-f368-4945-b046-4499a1da69d1
Detects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).
Author: Florian Roth (Nextron Systems)
· 2020-02-29 (modified 2023-01-02) · logsource: category=webserver · fce2c2e2-0fb5-41ab-a14c-5391e1fd70a5
Detects the exploitation of Microsoft Exchange vulnerability as described in CVE-2020-0688
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-08-12 (modified 2023-01-02) · logsource: category=webserver · fcf1101d-07c9-49b2-ad81-7e421ff96d80
Detects the exploitation of VMware Workspace ONE Access Authentication Bypass vulnerability as described in CVE-2022-31656
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users.
A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Author: Thomas Patzke
· 2017-08-05 (modified 2020-09-01) · logsource: product=django category=application · fd435618-981e-4a7c-81f8-f78ce480d616
Detects suspicious Django web application framework exceptions that could indicate exploitation attempts
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-12-22 · logsource: category=proxy · fdd7e904-7304-4616-a46a-e32f917c4be4
Detects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint
Author: X__Junior (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-10-20 · logsource: product=windows category=process_creation · ff0225a0-1d9a-4bae-ab26-6038b18bb6d4
Detects the use of argument injection in the Commvault qlogin command - potential exploitation for CVE-2025-57791.
An attacker can inject the `-localadmin` parameter via the password field to bypass authentication and gain a privileged token.
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
mediumtest
Author: Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT)
· 2023-11-28 · logsource: category=proxy · ff349b81-617f-4af4-924f-dbe8ea9bab41
Detects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs.