Techniques › T1190 › AN0220
AN0220 Analytic 0220
Linux · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Adversary exploits Apache/Nginx/app servers. Chain: (1) suspicious requests in access logs → (2) spike of 5xx or WAF blocks → (3) web server or interpreter (apache2/nginx/php-fpm/node/python) spawns /bin/sh, curl, wget, socat, or writes webshell → (4) outbound callback.</p>
- Detects
- T1190 Exploit Public-Facing Application
- Part of
- DET0080 Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress)
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| ApplicationLog:WebServer | /var/log/httpd/access_log, /var/log/apache2/access.log, /var/log/nginx/access.log with exploit indicators and burst errors | DC0038 Application Log Content |
| auditd:SYSCALL | execve | DC0032 Process Creation |
| NSM:Flow | HTTP payloads with SQLi/LFI/JNDI/deserialization indicators | DC0085 Network Traffic Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
WebProcList | server/interpreter names to watch (apache2, httpd, nginx, php-fpm, uwsgi, gunicorn, node). |
ChildToolList | post-exploitation binaries (sh, bash, curl, wget, python, perl, socat, nc). |
BurstThreshold | Rate of errors/requests per src_ip/uri to flag reconnaissance/exploit spray. |
TimeWindow | Exec/network correlation window. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2009-3960 | Adobe BlazeDS | Mapped |
| CVE-2010-2861 | Adobe ColdFusion | Mapped |
| CVE-2013-0625 | Adobe ColdFusion | Mapped |
| CVE-2013-0629 | Adobe ColdFusion | Mapped |
| CVE-2013-0631 | Adobe ColdFusion | Mapped |
| CVE-2013-0632 | Adobe ColdFusion | Mapped |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) | Mapped |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) | Mapped |
| CVE-2016-10033 | PHP PHPMailer | Mapped |
| CVE-2016-4437 | Apache Shiro | Mapped |
| CVE-2017-12637 | SAP NetWeaver | Mapped |
| CVE-2017-5638 | Apache Struts | Mapped |
| CVE-2017-9805 | Apache Struts | Mapped |
| CVE-2017-9822 | DotNetNuke (DNN) DotNetNuke (DNN) | Mapped |
| CVE-2018-11776 | Apache Struts | Mapped |
| CVE-2018-13379 | Fortinet FortiOS | Mapped |
| CVE-2018-15961 | Adobe ColdFusion | Mapped |
| CVE-2018-4939 | Adobe ColdFusion | Mapped |
| CVE-2018-6789 | Exim Exim | Mapped |
| CVE-2018-7600 | Drupal Drupal Core | Mapped |
| CVE-2019-0604 | Microsoft SharePoint | Mapped |
| CVE-2019-11634 | Citrix Workspace Application and Receiver for Windows | Mapped |
| CVE-2019-1653 | Cisco Small Business RV320 and RV325 Routers | Mapped |
| CVE-2019-17558 | Apache Solr | Mapped |
| CVE-2019-18935 | Progress Telerik UI for ASP.NET AJAX | Mapped |
| CVE-2020-0688 | Microsoft Exchange Server | Mapped |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products | Mapped |
| CVE-2020-17530 | Apache Struts | Mapped |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices | Mapped |
| CVE-2020-5902 | F5 BIG-IP | Stale |
| CVE-2021-21972 | VMware vCenter Server | Mapped |
| CVE-2021-21973 | VMware vCenter Server and Cloud Foundation | Mapped |
| CVE-2021-21975 | VMware vRealize Operations Manager API | Mapped |
| CVE-2021-22005 | VMware vCenter Server | Mapped |
| CVE-2021-22017 | VMware vCenter Server | Mapped |
| CVE-2021-22204 | Perl Exiftool | Mapped |
| CVE-2021-22205 | GitLab Community and Enterprise Editions | Mapped |
| CVE-2021-22893 | Ivanti Pulse Connect Secure | Mapped |
| CVE-2021-22986 | F5 BIG-IP and BIG-IQ Centralized Management | Mapped |
| CVE-2021-26085 | Atlassian Confluence Server | Mapped |
| CVE-2021-26858 | Microsoft Exchange Server | Mapped |
| CVE-2021-27065 | Microsoft Exchange Server | Mapped |
| CVE-2021-27102 | Accellion FTA | Mapped |
| CVE-2021-27103 | Accellion FTA | Mapped |
| CVE-2021-27104 | Accellion FTA | Mapped |
| CVE-2021-27860 | FatPipe WARP, IPVPN, and MPVPN software | Mapped |
| CVE-2021-31166 | Microsoft HTTP Protocol Stack | Mapped |
| CVE-2021-3129 | Laravel Ignition | Mapped |
| CVE-2021-34473 | Microsoft Exchange Server | Mapped |
| CVE-2021-34523 | Microsoft Exchange Server | Mapped |
| CVE-2021-35394 | Realtek Jungle Software Development Kit (SDK) | Mapped |
| CVE-2021-35464 | ForgeRock Access Management (AM) | Mapped |
| CVE-2021-36380 | Sunhillo SureLine | Mapped |
| CVE-2021-37415 | Zoho ManageEngine ServiceDesk Plus (SDP) | Mapped |
| CVE-2021-39144 | XStream XStream | Mapped |
| CVE-2021-39226 | Grafana Labs Grafana | Mapped |
| CVE-2021-40539 | Zoho ManageEngine | Mapped |
| CVE-2021-40655 | D-Link DIR-605 Router | Mapped |
| CVE-2021-44077 | Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | Mapped |
| CVE-2021-44228 | Apache Log4j2 | Mapped |
| CVE-2021-44515 | Zoho Desktop Central | Mapped |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) | Mapped |
| CVE-2021-45382 | D-Link Multiple Routers | Mapped |
| CVE-2022-0028 | Palo Alto Networks PAN-OS | Mapped |
| CVE-2022-1040 | Sophos Firewall | Mapped |
| CVE-2022-20700 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Mapped |
| CVE-2022-20708 | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Mapped |
| CVE-2022-20821 | Cisco IOS XR | Mapped |
| CVE-2022-22947 | VMware Spring Cloud Gateway | Mapped |
| CVE-2022-22963 | VMware Tanzu Spring Cloud | Mapped |
| CVE-2022-22965 | VMware Spring Framework | Mapped |
| CVE-2022-23131 | Zabbix Frontend | Mapped |
| CVE-2022-24086 | Adobe Commerce and Magento Open Source | Mapped |
| CVE-2022-26134 | Atlassian Confluence Server/Data Center | Mapped |
| CVE-2022-26258 | D-Link DIR-820L | Mapped |
| CVE-2022-26500 | Veeam Backup & Replication | Mapped |
| CVE-2022-26501 | Veeam Backup & Replication | Mapped |
| CVE-2022-28810 | Zoho ManageEngine | Mapped |
| CVE-2022-29464 | WSO2 Multiple Products | Mapped |
| CVE-2022-35914 | Teclib GLPI | Mapped |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center | Mapped |
| CVE-2022-39197 | Fortra Cobalt Strike | Mapped |
| CVE-2022-40684 | Fortinet Multiple Products | Mapped |
| CVE-2022-42475 | Fortinet FortiOS | Mapped |
| CVE-2022-42948 | Fortra Cobalt Strike | Mapped |
| CVE-2022-43939 | Hitachi Vantara Pentaho Business Analytics (BA) Server | Mapped |
| CVE-2022-47966 | Zoho ManageEngine | Mapped |
| CVE-2023-0669 | Fortra GoAnywhere MFT | Mapped |
| CVE-2023-20198 | Cisco IOS XE Web UI | Mapped |
| CVE-2023-20887 | VMware Aria Operations for Networks | Mapped |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server | Mapped |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server | Mapped |
| CVE-2023-22952 | SugarCRM Multiple Products | Stale |
| CVE-2023-26359 | Adobe ColdFusion | Mapped |
| CVE-2023-26360 | Adobe ColdFusion | Mapped |
| CVE-2023-27350 | PaperCut MF/NG | Mapped |
| CVE-2023-27524 | Apache Superset | Mapped |
| CVE-2023-27997 | Fortinet FortiOS and FortiProxy SSL-VPN | Mapped |
| CVE-2023-29298 | Adobe ColdFusion | Mapped |
| CVE-2023-29300 | Adobe ColdFusion | Mapped |
| CVE-2023-29492 | Novi Survey Novi Survey | Mapped |
| CVE-2023-33246 | Apache RocketMQ | Mapped |
| CVE-2023-34362 | Progress MOVEit Transfer | Mapped |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile (EPMM) | Mapped |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) | Mapped |
| CVE-2023-3519 | Citrix NetScaler ADC and NetScaler Gateway | Mapped |
| CVE-2023-36844 | Juniper Junos OS | Mapped |
| CVE-2023-36845 | Juniper Junos OS | Mapped |
| CVE-2023-36846 | Juniper Junos OS | Mapped |
| CVE-2023-36847 | Juniper Junos OS | Mapped |
| CVE-2023-36851 | Juniper Junos OS | Mapped |
| CVE-2023-38035 | Ivanti Sentry | Mapped |
| CVE-2023-38203 | Adobe ColdFusion | Mapped |
| CVE-2023-38205 | Adobe ColdFusion | Mapped |
| CVE-2023-38950 | ZKTeco BioTime | Mapped |
| CVE-2023-42793 | JetBrains TeamCity | Mapped |
| CVE-2023-44487 | IETF HTTP/2 | Mapped |
| CVE-2023-46604 | Apache ActiveMQ | Mapped |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure | Mapped |
| CVE-2023-48365 | Qlik Sense | Mapped |
| CVE-2023-48788 | Fortinet FortiClient EMS | Mapped |
| CVE-2023-49103 | ownCloud ownCloud graphapi | Mapped |
| CVE-2023-7101 | Spreadsheet::ParseExcel Spreadsheet::ParseExcel | Mapped |
| CVE-2024-0769 | D-Link DIR-859 Router | Mapped |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) | Mapped |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) | Mapped |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) | Mapped |
| CVE-2024-20353 | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Mapped |
| CVE-2024-20953 | Oracle Agile Product Lifecycle Management (PLM) | Mapped |
| CVE-2024-21762 | Fortinet FortiOS | Mapped |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure | Mapped |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons | Mapped |
| CVE-2024-27198 | JetBrains TeamCity | Mapped |
| CVE-2024-34102 | Adobe Commerce and Magento Open Source | Mapped |
| CVE-2024-38475 | Apache HTTP Server | Mapped |
| CVE-2024-4358 | Progress Telerik Report Server | Mapped |
| CVE-2024-4577 | PHP Group PHP | Mapped |
| CVE-2024-48248 | NAKIVO Backup and Replication | Mapped |
| CVE-2024-4879 | ServiceNow Utah, Vancouver, and Washington DC Now Platform | Mapped |
| CVE-2024-55550 | Mitel MiCollab | Mapped |
| CVE-2024-57727 | SimpleHelp SimpleHelp | Mapped |
| CVE-2025-0108 | Palo Alto Networks PAN-OS | Mapped |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | Mapped |
| CVE-2025-1316 | Edimax IC-7100 IP Camera | Mapped |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | Mapped |
| CVE-2025-23006 | SonicWall SMA1000 Appliances | Mapped |
| CVE-2025-25257 | Fortinet FortiWeb | Mapped |
| CVE-2025-34028 | Commvault Command Center | Mapped |
| CVE-2025-35939 | Craft CMS Craft CMS | Mapped |
| CVE-2025-42599 | Qualitia Active! Mail | Mapped |
| CVE-2025-42999 | SAP NetWeaver | Mapped |
| CVE-2025-4427 | Ivanti Endpoint Manager Mobile (EPMM) | Mapped |
| CVE-2025-4428 | Ivanti Endpoint Manager Mobile (EPMM) | Mapped |
| CVE-2025-49704 | Microsoft SharePoint | Mapped |
| CVE-2025-49706 | Microsoft SharePoint | Mapped |
| CVE-2025-53770 | Microsoft SharePoint | Mapped |
| CVE-2025-5777 | Citrix NetScaler ADC and Gateway | Mapped |