kevmap

Techniques › T1190

T1190 Exploit Public-Facing Application

initial access — Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
7
analytics
149
Sigma rules tagged attack.t1190
157
KEV CVEs mapped here
<p>Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.</p><p>Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers. Depending on the flaw being exploited, this may also involve Exploitation for Stealth or Exploitation for Client Execution.</p><p>If an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the Cloud Instance Metadata API), exploit container host access via Escape to Host, or take advantage of weak identity and access management policies.</p><p>Adversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses.</p><p>For websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2025-49704Microsoft SharePoint exploitation technique Mapped2025-07-22
CVE-2025-49706Microsoft SharePoint exploitation technique Mapped2025-07-22
CVE-2025-53770Microsoft SharePoint exploitation technique Mapped2025-07-20
CVE-2025-25257Fortinet FortiWeb exploitation technique Mapped2025-07-18
CVE-2025-5777Citrix NetScaler ADC and Gateway exploitation technique Mapped2025-07-10
CVE-2016-10033PHP PHPMailer exploitation technique Mapped2025-07-07
CVE-2024-0769D-Link DIR-859 Router exploitation technique Mapped2025-06-25
CVE-2025-35939Craft CMS Craft CMS exploitation technique Mapped2025-06-02
CVE-2023-38950ZKTeco BioTime exploitation technique Mapped2025-05-19
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) exploitation technique Mapped2025-05-19
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) exploitation technique Mapped2025-05-19
CVE-2025-42999SAP NetWeaver exploitation technique Mapped2025-05-15
CVE-2025-34028Commvault Command Center exploitation technique Mapped2025-05-02
CVE-2024-38475Apache HTTP Server exploitation technique Mapped2025-05-01
CVE-2025-42599Qualitia Active! Mail exploitation technique Mapped2025-04-28
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA Gateways exploitation technique Mapped2025-04-04
CVE-2017-12637SAP NetWeaver exploitation technique Mapped2025-03-19
CVE-2024-48248NAKIVO Backup and Replication exploitation technique Mapped2025-03-19
CVE-2025-1316Edimax IC-7100 IP Camera exploitation technique Mapped2025-03-19
CVE-2024-13161Ivanti Endpoint Manager (EPM) exploitation technique Mapped2025-03-10
CVE-2024-13160Ivanti Endpoint Manager (EPM) exploitation technique Mapped2025-03-10
CVE-2024-13159Ivanti Endpoint Manager (EPM) exploitation technique Mapped2025-03-10
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) Server exploitation technique Mapped2025-03-03
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM) exploitation technique Mapped2025-02-24
CVE-2025-0108Palo Alto Networks PAN-OS exploitation technique Mapped2025-02-18
CVE-2024-57727SimpleHelp SimpleHelp exploitation technique Mapped2025-02-13
CVE-2025-23006SonicWall SMA1000 Appliances exploitation technique Mapped2025-01-24
CVE-2023-48365Qlik Sense exploitation technique Mapped2025-01-13
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA Gateways exploitation technique Mapped2025-01-08
CVE-2024-55550Mitel MiCollab exploitation technique Mapped2025-01-07
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now Platform primary impact Mapped2024-07-29
CVE-2024-34102Adobe Commerce and Magento Open Source exploitation technique Mapped2024-07-17
CVE-2024-4358Progress Telerik Report Server exploitation technique Mapped2024-06-13
CVE-2024-4577PHP Group PHP exploitation technique Mapped2024-06-12
CVE-2021-40655D-Link DIR-605 Router exploitation technique Mapped2024-05-16
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) exploitation technique Mapped2024-04-24
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) exploitation technique Mapped2024-03-25
CVE-2023-48788Fortinet FortiClient EMS exploitation technique Mapped2024-03-25
CVE-2024-27198JetBrains TeamCity exploitation technique Mapped2024-03-07
CVE-2021-36380Sunhillo SureLine exploitation technique Mapped2024-03-05
CVE-2024-21762Fortinet FortiOS exploitation technique Mapped2024-02-09
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and Neurons exploitation technique Mapped2024-01-31
CVE-2023-46805Ivanti Connect Secure and Policy Secure exploitation technique Mapped2024-01-10
CVE-2024-21887Ivanti Connect Secure and Policy Secure exploitation technique Mapped2024-01-10
CVE-2023-27524Apache Superset exploitation technique Mapped2024-01-08
CVE-2023-29300Adobe ColdFusion exploitation technique Mapped2024-01-08
CVE-2023-38203Adobe ColdFusion exploitation technique Mapped2024-01-08
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcel exploitation technique Mapped2024-01-02
CVE-2023-49103ownCloud ownCloud graphapi exploitation technique Mapped2023-11-30
CVE-2023-36844Juniper Junos OS primary impact Mapped2023-11-13
CVE-2023-36845Juniper Junos OS exploitation technique Mapped2023-11-13
CVE-2023-36846Juniper Junos OS exploitation technique Mapped2023-11-13
CVE-2023-36847Juniper Junos OS exploitation technique Mapped2023-11-13
CVE-2023-36851Juniper Junos OS exploitation technique Mapped2023-11-13
CVE-2023-22518Atlassian Confluence Data Center and Server exploitation technique Mapped2023-11-07
CVE-2023-46604Apache ActiveMQ exploitation technique Mapped2023-11-02
CVE-2023-20198Cisco IOS XE Web UI exploitation technique Mapped2023-10-16
CVE-2023-44487IETF HTTP/2 exploitation technique Mapped2023-10-10
CVE-2023-22515Atlassian Confluence Data Center and Server exploitation technique Mapped2023-10-05
CVE-2023-42793JetBrains TeamCity exploitation technique Mapped2023-10-04
CVE-2021-3129Laravel Ignition exploitation technique Mapped2023-09-18
CVE-2023-33246Apache RocketMQ exploitation technique Mapped2023-09-06
CVE-2023-38035Ivanti Sentry exploitation technique Mapped2023-08-22
CVE-2023-26359Adobe ColdFusion exploitation technique Mapped2023-08-21
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) exploitation technique Mapped2023-07-31
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) exploitation technique Mapped2023-07-25
CVE-2023-29298Adobe ColdFusion exploitation technique Mapped2023-07-20
CVE-2023-38205Adobe ColdFusion exploitation technique Mapped2023-07-20
CVE-2023-3519Citrix NetScaler ADC and NetScaler Gateway exploitation technique Mapped2023-07-19
CVE-2023-20887VMware Aria Operations for Networks exploitation technique Mapped2023-06-22
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN exploitation technique Mapped2023-06-13
CVE-2023-34362Progress MOVEit Transfer exploitation technique Mapped2023-06-02
CVE-2023-27350PaperCut MF/NG exploitation technique Mapped2023-04-21
CVE-2023-29492Novi Survey Novi Survey exploitation technique Mapped2023-04-13
CVE-2022-42948Fortra Cobalt Strike exploitation technique Mapped2023-03-30
CVE-2022-39197Fortra Cobalt Strike exploitation technique Mapped2023-03-30
CVE-2023-26360Adobe ColdFusion exploitation technique Mapped2023-03-15
CVE-2021-39144XStream XStream exploitation technique Mapped2023-03-10
CVE-2022-28810Zoho ManageEngine exploitation technique Mapped2023-03-07
CVE-2022-35914Teclib GLPI exploitation technique Mapped2023-03-07
CVE-2023-0669Fortra GoAnywhere MFT exploitation technique Mapped2023-02-10
CVE-2023-22952SugarCRM Multiple Products exploitation technique Stale2023-02-02
CVE-2022-47966Zoho ManageEngine exploitation technique Mapped2023-01-23
CVE-2022-42475Fortinet FortiOS exploitation technique Mapped2022-12-13
CVE-2022-26500Veeam Backup & Replication exploitation technique Mapped2022-12-13
CVE-2022-26501Veeam Backup & Replication exploitation technique Mapped2022-12-13
CVE-2022-40684Fortinet Multiple Products exploitation technique Mapped2022-10-11
CVE-2022-36804Atlassian Bitbucket Server and Data Center exploitation technique Mapped2022-09-30
CVE-2022-26258D-Link DIR-820L exploitation technique Mapped2022-09-08
CVE-2022-22963VMware Tanzu Spring Cloud exploitation technique Mapped2022-08-25
CVE-2021-39226Grafana Labs Grafana exploitation technique Mapped2022-08-25
CVE-2022-0028Palo Alto Networks PAN-OS exploitation technique Mapped2022-08-22
CVE-2022-26134Atlassian Confluence Server/Data Center exploitation technique Mapped2022-06-02
CVE-2022-20821Cisco IOS XR exploitation technique Mapped2022-05-23
CVE-2022-22947VMware Spring Cloud Gateway exploitation technique Mapped2022-05-16
CVE-2022-29464WSO2 Multiple Products exploitation technique Mapped2022-04-25
CVE-2021-31166Microsoft HTTP Protocol Stack exploitation technique Mapped2022-04-06
CVE-2022-22965VMware Spring Framework exploitation technique Mapped2022-04-04
CVE-2021-45382D-Link Multiple Routers exploitation technique Mapped2022-04-04
CVE-2022-1040Sophos Firewall exploitation technique Mapped2022-03-31
CVE-2021-26085Atlassian Confluence Server exploitation technique Mapped2022-03-28
CVE-2010-2861Adobe ColdFusion exploitation technique Mapped2022-03-25
CVE-2021-21973VMware vCenter Server and Cloud Foundation exploitation technique Mapped2022-03-07
CVE-2013-0631Adobe ColdFusion exploitation technique Mapped2022-03-07
CVE-2013-0629Adobe ColdFusion exploitation technique Mapped2022-03-07
CVE-2013-0625Adobe ColdFusion exploitation technique Mapped2022-03-07
CVE-2009-3960Adobe BlazeDS exploitation technique Mapped2022-03-07
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers exploitation technique Mapped2022-03-03
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers exploitation technique Mapped2022-03-03
CVE-2013-0632Adobe ColdFusion exploitation technique Mapped2022-03-03
CVE-2022-23131Zabbix Frontend exploitation technique Mapped2022-02-22
CVE-2022-24086Adobe Commerce and Magento Open Source exploitation technique Mapped2022-02-15
CVE-2014-6271GNU Bourne-Again Shell (Bash) exploitation technique Mapped2022-01-28
CVE-2014-7169GNU Bourne-Again Shell (Bash) exploitation technique Mapped2022-01-28
CVE-2021-21975VMware vRealize Operations Manager API exploitation technique Mapped2022-01-18
CVE-2021-22017VMware vCenter Server exploitation technique Mapped2022-01-10
CVE-2021-27860FatPipe WARP, IPVPN, and MPVPN software exploitation technique Mapped2022-01-10
CVE-2021-44515Zoho Desktop Central exploitation technique Mapped2021-12-10
CVE-2021-35394Realtek Jungle Software Development Kit (SDK) exploitation technique Mapped2021-12-10
CVE-2021-44228Apache Log4j2 exploitation technique Mapped2021-12-10
CVE-2021-37415Zoho ManageEngine ServiceDesk Plus (SDP) exploitation technique Mapped2021-12-01
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus exploitation technique Mapped2021-12-01
CVE-2021-22204Perl Exiftool exploitation technique Mapped2021-11-17
CVE-2021-27104Accellion FTA exploitation technique Mapped2021-11-03
CVE-2021-27102Accellion FTA exploitation technique Mapped2021-11-03
CVE-2021-27103Accellion FTA exploitation technique Mapped2021-11-03
CVE-2018-4939Adobe ColdFusion primary impact Mapped2021-11-03
CVE-2018-15961Adobe ColdFusion exploitation technique Mapped2021-11-03
CVE-2017-9805Apache Struts exploitation technique Mapped2021-11-03
CVE-2016-4437Apache Shiro exploitation technique Mapped2021-11-03
CVE-2019-17558Apache Solr exploitation technique Mapped2021-11-03
CVE-2020-17530Apache Struts exploitation technique Mapped2021-11-03
CVE-2017-5638Apache Struts exploitation technique Mapped2021-11-03
CVE-2018-11776Apache Struts exploitation technique Mapped2021-11-03
CVE-2019-1653Cisco Small Business RV320 and RV325 Routers exploitation technique Mapped2021-11-03
CVE-2019-11634Citrix Workspace Application and Receiver for Windows exploitation technique Mapped2021-11-03
CVE-2020-29557D-Link DIR-825 R1 Devices exploitation technique Mapped2021-11-03
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN) exploitation technique Mapped2021-11-03
CVE-2018-7600Drupal Drupal Core exploitation technique Mapped2021-11-03
CVE-2021-22205GitLab Community and Enterprise Editions exploitation technique Mapped2021-11-03
CVE-2018-6789Exim Exim exploitation technique Mapped2021-11-03
CVE-2020-5902F5 BIG-IP exploitation technique Stale2021-11-03
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized Management exploitation technique Mapped2021-11-03
CVE-2021-35464ForgeRock Access Management (AM) exploitation technique Mapped2021-11-03
CVE-2018-13379Fortinet FortiOS exploitation technique Mapped2021-11-03
CVE-2020-15505Ivanti MobileIron Multiple Products exploitation technique Mapped2021-11-03
CVE-2021-34523Microsoft Exchange Server exploitation technique Mapped2021-11-03
CVE-2020-0688Microsoft Exchange Server exploitation technique Mapped2021-11-03
CVE-2021-34473Microsoft Exchange Server exploitation technique Mapped2021-11-03
CVE-2021-26858Microsoft Exchange Server exploitation technique Mapped2021-11-03
CVE-2021-27065Microsoft Exchange Server exploitation technique Mapped2021-11-03
CVE-2019-0604Microsoft SharePoint exploitation technique Mapped2021-11-03
CVE-2019-18935Progress Telerik UI for ASP.NET AJAX exploitation technique Mapped2021-11-03
CVE-2021-22893Ivanti Pulse Connect Secure exploitation technique Mapped2021-11-03
CVE-2021-22005VMware vCenter Server exploitation technique Mapped2021-11-03
CVE-2021-21972VMware vCenter Server exploitation technique Mapped2021-11-03
CVE-2021-40539Zoho ManageEngine exploitation technique Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1190

Author: Nasreddine Bencherchali (Nextron Systems) · 2023-05-30 · logsource: category=webserver · 043c1609-0e32-4462-a6f2-5a0c2da3fafe
Detects a potential exploitation attempt of CVE-2023-25717 a Remote Code Execution via an unauthenticated HTTP GET Request, in Ruckus Wireless Admin
Techniques: T1190
CVE tags: CVE-2023-25717
Author: @gott_cyber · 2022-12-11 (modified 2023-03-24) · logsource: category=webserver · 0bbcd74b-0596-41a4-94a0-4e88a76ffdb3
Detects exploitation attempt of the CVE-2021-27905 which affects all Apache Solr versions prior to and including 8.8.1.
Techniques: T1190
CVE tags: CVE-2021-27905
Author: Florian Roth (Nextron Systems) · 2020-07-10 (modified 2023-01-02) · logsource: category=webserver · 0d0d9a8a-a49e-4e27-b061-7ce4b936cfb7
Detects exploitation attempt against Citrix Netscaler, Application Delivery Controller (ADS) and Citrix Gateway exploiting vulnerabilities reported as CVE-2020-8193 and CVE-2020-8195
Techniques: T1190
CVE tags: CVE-2020-8193CVE-2020-8195
Author: Thomas Patzke · 2017-08-06 (modified 2020-09-01) · logsource: product=ruby_on_rails category=application · 0d2c3d4c-4b48-4ac3-8f23-ea845746bb1a
Detects suspicious Ruby on Rails exceptions that could indicate exploitation attempts
Techniques: T1190
Author: Bhabesh Raj · 2023-02-23 · logsource: category=webserver · 0e1ebc5a-15d0-4bf6-8199-b2535397433a
Detects the potential exploitation attempt of CVE-2023-23752 an Improper access check, in web service endpoints in Joomla
Techniques: T1190
CVE tags: CVE-2023-23752
Author: Nisarg Suthar · 2025-08-01 · logsource: product=windows category=process_creation · 0fdc7c7f-c690-4217-9ae3-31f5156eed72
Detects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.
CVE tags: CVE-2025-54309
Author: Florian Roth (Nextron Systems) · 2019-05-22 (modified 2023-01-25) · logsource: product=windows category=process_creation · 1012f107-b8f1-4271-af30-5aed2de89b39
Detects a process spawned by the terminal service server process (this could be an indicator for an exploitation of CVE-2019-0708)
Techniques: T1190T1210
Author: jamesc-grafana · 2024-07-11 · logsource: product=aws service=cloudtrail · 14f3f1c8-02d5-43a2-a191-91ffb52d3015
Detects changes to the security group entries for RDS databases. This can indicate that a misconfiguration has occurred which potentially exposes the database to the public internet, a wider audience within the VPC or that removal of valid rules has occurred which could impact the availability of the database to legitimate services and users.
Techniques: T1190
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-20 · logsource: category=proxy · 15697955-6a29-47ca-92e9-0e05efae3260
Detects suspicious requests to Cisco ASA WebVpn via proxy logs associated with CVE-2025-20333 and CVE-2025-20362 exploitation.
Techniques: T1190
CVE tags: CVE-2025-20333CVE-2025-20362
Author: Bhabesh Raj · 2021-01-25 (modified 2023-01-02) · logsource: category=webserver · 15c312b9-00d0-4feb-8870-7d940a4bdc5e
Detects the exploitation of the TerraMaster TOS vulnerability described in CVE-2020-28188
Techniques: T1190
CVE tags: CVE-2020-28188
Author: Moti Harmats · 2023-02-11 · logsource: product=velocity category=application · 16c86189-b556-4ee8-b4c7-7e350a195a4f
Detects exceptions in velocity template renderer, this most likely happens due to dynamic rendering of user input and may lead to RCE.
Techniques: T1190
Author: Bhabesh Raj · 2021-02-24 (modified 2023-01-02) · logsource: category=webserver · 179ed852-0f9b-4009-93a7-68475910fd86
Detects the exploitation of VSphere Remote Code Execution vulnerability as described in CVE-2021-21972
Techniques: T1190
CVE tags: CVE-2021-21972
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-12-22 (modified 2023-01-02) · logsource: category=webserver · 181f49fa-0b21-4665-a98c-a57025ebb8c7
Detects exploitation attempt of the OWASSRF variant targeting exchange servers It uses the OWA endpoint to access the powershell backend endpoint
Techniques: T1190
Author: Nasreddine Bencherchali (Nextron Systems), Tim Shelton · 2022-07-19 (modified 2026-06-11) · logsource: category=webserver · 19aa4f58-94ca-45ff-bc34-92e533c0994a
Detects known suspicious (default) user-agents related to scanning/recon tools
Techniques: T1190
Author: Thomas Patzke · 2017-08-12 (modified 2020-09-01) · logsource: product=python category=application · 19aefed0-ffd4-47dc-a7fc-f8b1425e84f9
Generic rule for SQL exceptions in Python according to PEP 249
Techniques: T1190
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-07-19 (modified 2023-01-02) · logsource: category=webserver · 1a9a04fd-02d1-465c-abad-d733fd409f9c
Detects attempts to exploit an apache spark server via CVE-2014-6287 from a weblogs perspective
Techniques: T1190
CVE tags: CVE-2022-33891
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-01-20 · logsource: category=webserver · 1b2eeb27-949b-4704-8bfa-d8e5cfa045a1
Detects potential exploitation attempts that target the Centos Web Panel 7 Unauthenticated Remote Code Execution CVE-2022-44877
Techniques: T1190
CVE tags: CVE-2022-44877
Author: Andreas Braathen (mnemonic.io) · 2023-11-14 · logsource: product=windows category=process_creation · 1ddaa9a4-eb0b-4398-a9fe-7b018f9e23db
Detects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
Techniques: T1059T1190
CVE tags: CVE-2023-22518
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-12-22 · logsource: category=proxy · 1ddf4596-1908-43c9-add2-1d2c2fcc4797
Detects exploitation attempt of the OWASSRF variant targeting exchange servers It uses the OWA endpoint to access the powershell backend endpoint
Techniques: T1190
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-07-24 · logsource: product=windows category=file_event · 1f0489be-b496-4ddf-b3a9-5900f2044e9c
Detects suspicious file writes to SharePoint layouts directory which could indicate webshell activity or post-exploitation. This behavior has been observed in the exploitation of SharePoint vulnerabilities such as CVE-2025-49704, CVE-2025-49706 or CVE-2025-53770.
Techniques: T1190T1505.003
Author: Florian Roth (Nextron Systems) · 2021-11-17 (modified 2023-01-02) · logsource: category=webserver · 20c6ed1c-f7f0-4ea3-aa65-4f198e6acb0f
Detects exploitation attempts of Sitecore Experience Platform Pre-Auth RCE CVE-2021-42237 found in Report.ashx
Techniques: T1190
CVE tags: CVE-2021-42237
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC · 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 21541900-27a9-4454-9c4c-3f0a4240344a
Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Techniques: T1068T1190T1203
Author: Florian Roth (Nextron Systems), Rich Warren · 2021-08-07 (modified 2023-01-02) · logsource: category=webserver · 23eee45e-933b-49f9-ae1b-df706d2d52ef
Detects URL patterns that could be found in ProxyShell exploitation attempts against Exchange servers (failed and successful)
Techniques: T1190
Author: Bhabesh Raj · 2021-09-08 (modified 2023-02-13) · logsource: product=windows category=process_creation · 245f92e3-c4da-45f1-9070-bc552e06db11
Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084
Techniques: T1190T1059
CVE tags: CVE-2021-26084
Author: Swachchhanda Shrawan Poudel (Nextron Systems), Nasreddine Bencherchali · 2025-12-05 · logsource: product=windows category=process_creation · 271de298-cc0e-4842-acd8-079a0a99ea65
Detects suspicious child processes started by Node.js server processes on Windows, which may indicate exploitation of vulnerabilities like CVE-2025-55182 (React2Shell). Attackers can abuse the Node.js 'child_process' module to run system commands or scripts using methods such as spawn(), exec(), execFile(), fork(), or execSync(). If execSync() or exec() is used in the exploit, the command line often shows a shell (e.g., cmd.exe /d /s /c ...) running a suspicious command unless other shells are explicitly invoked. For other methods, the spawned process appears directly in the Image field unless a shell is explicitly used.
Techniques: T1059T1190
CVE tags: CVE-2025-55182
Author: Andreas Braathen (mnemonic.io) · 2023-11-14 · logsource: category=proxy · 27d2cdde-9778-490e-91ec-9bd0be6e8cc6
Detects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
Techniques: T1190
CVE tags: CVE-2023-22518
Author: Florian Roth (Nextron Systems) · 2019-11-18 (modified 2023-01-02) · logsource: category=webserver · 2dbc10d7-a797-49a8-8776-49efa6442e60
Detects CVE-2019-11510 exploitation attempt - URI contains Guacamole
Techniques: T1190
CVE tags: CVE-2019-11510
Author: daffainfo, Florian Roth · 2021-10-05 (modified 2023-01-02) · logsource: category=webserver · 3007fec6-e761-4319-91af-e32e20ac43f5
Detects exploitation of flaw in path normalization in Apache HTTP server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the expected document root. If files outside of the document root are not protected by "require all denied" these requests can succeed. Additionally this flaw could leak the source of interpreted files like CGI scripts. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions.
Techniques: T1190
CVE tags: CVE-2021-41773
Author: Sergio Palacios Dominguez, Nasreddine Bencherchali (Nextron Systems) · 2023-07-28 · logsource: category=webserver · 31e4e649-7394-4fd2-9ae7-dbc61eebb550
Detects indicators of potential exploitation of CVE-2023-27997 in Frotigate weblogs. To avoid false positives it is best to look for successive requests to the endpoints mentioned as well as weird values of the "enc" parameter
Techniques: T1190
CVE tags: CVE-2023-27997
Author: Florian Roth (Nextron Systems) · 2017-07-05 (modified 2021-11-27) · logsource: product=linux service=vsftpd · 377f33a1-4b36-4ee1-acee-1dbe4b43cfbe
Detects suspicious VSFTPD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
Techniques: T1190
Author: Florian Roth (Nextron Systems) · 2018-07-22 (modified 2023-01-02) · logsource: category=webserver · 37e8369b-43bb-4bf8-83b6-6dd43bda2000
Detects access to a webshell dropped into a keystore folder on the WebLogic server
Techniques: T1190T1505.003
CVE tags: CVE-2018-2894
Author: Sittikorn S, Nuttakorn T · 2022-12-13 (modified 2023-03-24) · logsource: category=webserver · 38825179-3c78-4fed-b222-2e2166b926b1
Detects potential exploitation of CVE-2021-260841 a Confluence RCE using OGNL injection
Techniques: T1190
CVE tags: CVE-2021-26084
Author: @kostastsale · 2022-01-14 · logsource: product=windows category=process_creation · 3eb91f0a-0060-424a-a676-59f5fdd75610
Detects potential initial exploitation attempts against VMware Horizon deployments running a vulnerable versions of Log4j.
Techniques: T1190
CVE tags: CVE-2021-44228
Author: Florian Roth (Nextron Systems) · 2021-12-12 (modified 2022-12-25) · logsource: category=webserver · 412d55bc-7737-4d25-9542-5b396867ce55
Detects exploitation attempt using the JNDI-Exploit-Kit
Techniques: T1190
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-05-20 · logsource: category=webserver · 41956f7c-7a6b-46d6-b6bb-da6eb2e83fbe
Detects potential exploitation of a chained vulnerability attack targeting Ivanti EPMM 12.5.0.0. CVE-2025-4427 allows unauthenticated access to protected API endpoints via an authentication bypass, which can then be leveraged to trigger CVE-2025-4428 — a remote code execution vulnerability through template injection. This sequence enables unauthenticated remote code execution, significantly increasing the impact of exploitation.
Techniques: T1190T1203
CVE tags: CVE-2025-4427CVE-2025-4428
Author: Huntress Labs, Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-10-31 · logsource: product=windows category=process_creation · 43259cc4-1b80-4931-bd98-baea01afc196
Detects the creation of command-line interpreters (cmd.exe, powershell.exe) as child processes of Windows Server Update Services (WSUS) related process wsusservice.exe. This behavior is a key indicator of exploitation for the critical remote code execution vulnerability such as CVE-2025-59287, where attackers spawn shells to conduct reconnaissance and further post-exploitation activities.
Techniques: T1190T1203
CVE tags: CVE-2025-59287
Author: Florian Roth (Nextron Systems) · 2020-07-05 (modified 2023-01-02) · logsource: category=webserver · 44b53b1c-e60f-4a7b-948e-3435a7918478
Detects the exploitation attempt of the vulnerability found in F5 BIG-IP and described in CVE-2020-5902
Techniques: T1190
CVE tags: CVE-2020-5902
Author: Craig Sweeney, Matt Anderson, Jose Oregon, Tim Kasper, Faith Stratton, Samantha Shaw, Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-04-10 · logsource: product=windows category=process_creation · 459628e3-1b00-4e9b-9e5b-7da8961aea35
Detects suspicious child processes spawned by the CrushFTP service that may indicate exploitation of remote code execution vulnerabilities such as CVE-2025-31161, where attackers can achieve RCE through crafted HTTP requests. The detection focuses on commonly abused Windows executables (like powershell.exe, cmd.exe etc.) that attackers typically use post-exploitation to execute malicious commands.
CVE tags: CVE-2025-31161
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-07-21 · logsource: category=webserver · 48d053db-6a56-4866-b60d-0975647050ed
Detects access to vulnerable SharePoint components potentially being exploited in CVE-2025-53770 through IIS web server logs. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
Techniques: T1190
CVE tags: CVE-2025-53770
Author: Moti Harmats · 2023-02-11 · logsource: product=jvm category=application · 4d0af518-828e-4a04-a751-a7d03f3046ad
Detects potential OGNL Injection exploitation, which may lead to RCE. OGNL is an expression language that is supported in many JVM based systems. OGNL Injection is the reason for some high profile RCE's such as Apache Struts (CVE-2017-5638) and Confluence (CVE-2022-26134)
Techniques: T1190
CVE tags: CVE-2017-5638CVE-2022-26134
Author: Saw Win Naung, Nasreddine Bencherchali (Nextron Systems), Thurein Oo (Yoma Bank) · 2020-02-22 (modified 2023-09-04) · logsource: category=webserver · 5513deaf-f49a-46c2-a6c8-3f111b5cb453
Detects potential SQL injection attempts via GET requests in access logs.
Techniques: T1190
Author: Sittikorn S · 2021-06-29 (modified 2023-01-02) · logsource: category=webserver · 5525edac-f599-4bfd-b926-3fa69860e766
This rule detects exploitation attempts using Pulse Connect Secure(PCS) vulnerability (CVE-2021-22893)
Techniques: T1190
CVE tags: CVE-2021-22893
Author: @kostastsale · 2022-04-25 · logsource: product=windows category=process_creation · 5660d8db-6e25-411f-b92f-094420168a5d
Detects potential exploitation attempt of CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access and Identity Manager. As reported by Morphisec, part of the attack chain, threat actors used PowerShell commands that executed as a child processes of the legitimate Tomcat "prunsrv.exe" process application.
Techniques: T1059.006T1190
CVE tags: CVE-2022-22954
Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Christian Burkard (Nextron Systems) · 2021-08-30 (modified 2023-01-02) · logsource: category=webserver · 56973b50-3382-4b56-bdf5-f51a3183797a
Detects the exploitation of Microsoft Exchange ProxyToken vulnerability as described in CVE-2021-33766
Techniques: T1190
CVE tags: CVE-2021-33766
Author: frack113, Harjot Singh, "@cyb3rjy0t" (update) · 2022-06-04 (modified 2023-01-19) · logsource: category=webserver · 583aa0a2-30b1-4d62-8bf3-ab73689efe6c
Detects possible Java payloads in web access logs
Techniques: T1190
CVE tags: CVE-2022-26134CVE-2021-26084
Author: Bhabesh Raj, Tim Shelton · 2020-12-27 (modified 2023-01-02) · logsource: category=webserver · 5a35116f-43bc-4901-b62d-ef131f42a9af
Detects CVE-2020-10148 SolarWinds Orion API authentication bypass attempts
Techniques: T1190
CVE tags: CVE-2020-10148
Author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-04-28 · logsource: product=windows category=process_creation · 5b304bcb-ac33-49d0-87af-fa1b3ca94333
Detects suspicious child processes spawned by SAP NetWeaver that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
Techniques: T1190T1059.003
CVE tags: CVE-2025-31324
Author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-04-28 · logsource: product=linux category=file_event · 5b91409c-cb18-4ab6-ac75-c5759f998409
Detects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
Techniques: T1190T1059.003
CVE tags: CVE-2025-31324
Author: Andreas Hunkeler (@Karneades), Markus Neis · 2021-05-20 (modified 2022-07-14) · logsource: product=windows category=process_creation · 5cc2cda8-f261-4d88-a2de-e9e193c86716
Detects suspicious processes including shells spawnd from WinRM host process
Techniques: T1190
Author: Florian Roth (Nextron Systems) · 2021-12-10 (modified 2022-02-06) · logsource: category=webserver · 5ea8faa8-db8b-45be-89b0-151b84c82702
Detects exploitation attempt against log4j RCE vulnerability reported as CVE-2021-44228 (Log4Shell)
Techniques: T1190
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-09-29 (modified 2023-01-02) · logsource: category=webserver · 65c0a0ab-d675-4441-bd6b-d3db226a2685
Detects attempts to exploit the Atlassian Bitbucket Command Injection CVE-2022-36804
Techniques: T1190
CVE tags: CVE-2022-36804
Author: Tobias Michalski (Nextron Systems), Max Altgelt (Nextron Systems) · 2021-09-20 (modified 2023-01-02) · logsource: category=webserver · 6702b13c-e421-44cc-ab33-42cc25570f11
Detects suspicious access to URLs that was noticed in cases in which attackers exploitated the ADSelfService vulnerability CVE-2021-40539
Techniques: T1190
CVE tags: CVE-2021-40539
Author: Florian Roth (Nextron Systems) · 2021-03-03 (modified 2023-01-02) · logsource: category=webserver · 67bce556-312f-4c81-9162-c3c9ff2599b2
Detects exploitation attempts in Exchange server logs as described in blog posts reporting on HAFNIUM group activity
Techniques: T1190
Author: Bhabesh Raj · 2021-01-20 (modified 2023-01-02) · logsource: category=webserver · 687f6504-7f44-4549-91fc-f07bab065821
Detects the exploitation of the WebLogic server vulnerability described in CVE-2021-2109
Techniques: T1190
CVE tags: CVE-2021-2109
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 6991bc2b-ae2e-447f-bc55-3a1ba04c14e5
Detects instances where an FTP service on an OpenCanary node has had a login attempt.
Techniques: T1190T1021
Author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-04-28 · logsource: product=linux category=process_creation · 69dea60b-2deb-4c9e-a685-ad542f4367f9
Detects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
Techniques: T1190T1059.003
CVE tags: CVE-2025-31324
Author: Florian Roth (Nextron Systems) · 2022-10-04 · logsource: product=windows category=file_event · 6b269392-9eba-40b5-acb6-55c882b20ba6
Detects suspicious file type dropped by an Exchange component in IIS
Techniques: T1190T1505.003
Author: MSFT (idea), Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-10-07 · logsource: product=windows category=process_creation · 6c76b3d0-afe4-4870-9443-ffe6773c5fef
Detects suspicious command execution by child processes of the GoAnywhere Managed File Transfer (MFT) application, which may indicate exploitation such as CVE-2025-10035. This behavior is indicative of post-exploitation activity related to CVE-2025-10035, as observed in campaigns by the threat actor Storm-1175.
CVE tags: CVE-2025-10035
Author: Nasreddine Bencherchali (Nextron Systems), Rohit Jain · 2024-06-25 · logsource: category=proxy · 6c7defa9-69f8-4c34-b815-41fce3931754
Detects potential exploitation attempt of CVE-2023-1389 an Unauthenticated Command Injection in TP-Link Archer AX21.
Techniques: T1190
CVE tags: CVE-2023-1389
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali · 2023-01-21 · logsource: product=windows category=process_creation · 6d5b8176-d87d-4402-8af4-53aee9db7b5d
Detects potential exploitation attempt of undocumented Windows Server Pre Auth Remote Code Execution (RCE)
Techniques: T1190
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC · 2021-10-15 (modified 2022-10-05) · logsource: product=linux category=process_creation · 6eea1bf6-f8d2-488a-a742-e6ef6c1b67db
Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell. Script being executed gets created as a temp file in /tmp folder with a scx* prefix. Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/. The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
Techniques: T1068T1190T1203
Author: Florian Roth (Nextron Systems) · 2021-01-25 (modified 2023-04-27) · logsource: category=webserver · 6f55f047-112b-4101-ad32-43913f52db46
Detects exploitation attempts of the SonicWall Jarrewrite Exploit
Techniques: T1190
Author: jamesc-grafana · 2024-07-11 · logsource: product=aws service=cloudtrail · 6fb77778-040f-4015-9440-572aa9b6b580
Detects when an account makes changes to the ingress or egress rules of a security group. This can indicate that an attacker is attempting to open up new attack vectors in the account, that they are trying to exfiltrate data over the network, or that they are trying to allow machines in that VPC/Subnet to contact a C&C server.
Techniques: T1190
Author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber) · 2026-04-30 · logsource: category=webserver · 6fd25dd1-527b-47c8-baa4-2a0e77279c6f
Detects inbound web requests using the "libredtail-http" User-Agent. libredtail-http is a unique User-Agent string associated with a campaign of automated, malicious scans and attacks targeting exposed container environments and web applications,notably identified in activities stemming from late 2024 through early 2026. It is primarily used by the RedTail cryptominer malware to identify and exploit vulnerabilities for deploying cryptocurrency miners.
Techniques: T1190
Author: Florian Roth (Nextron Systems) · 2022-02-25 · logsource: product=windows category=file_event · 7280c9f3-a5af-45d0-916a-bc01cb4151c9
Detects suspicious activity in which the MSExchangeMailboxReplication process writes .asp and .apsx files to disk, which could be a sign of ProxyShell exploitation
Techniques: T1190T1505.003
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-12-27 (modified 2023-01-02) · logsource: category=webserver · 738cb115-881f-4df3-82cc-56ab02fc5192
Detects potential exploitation attempts that target the Cacti Command Injection CVE-2022-46169
Techniques: T1190
CVE tags: CVE-2022-46169
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-07-21 · logsource: product=windows category=process_creation · 7477881c-ec3b-49d6-aced-7255944e5c59
Detects potential exploitation of CVE-2025-53770 by identifying indicators such as suspicious command lines discovered in Post-Exploitation activities. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
Techniques: T1190
CVE tags: CVE-2025-53770
Author: Subhash Popuri (@pbssubhash), Florian Roth (Nextron Systems), Thurein Oo, Nasreddine Bencherchali (Nextron Systems) · 2021-09-25 (modified 2023-08-31) · logsource: category=webserver · 7745c2ea-24a5-4290-b680-04359cb84b35
Detects path traversal exploitation attempts
Techniques: T1190
Author: Bhabesh Raj · 2020-03-10 (modified 2023-01-02) · logsource: category=webserver · 77586a7f-7ea4-4c41-b19c-820140b84ca9
Detects the exploitation of the VMware View Planner vulnerability described in CVE-2021-21978
Techniques: T1190
CVE tags: CVE-2021-21978
Author: jamesc-grafana · 2024-07-11 · logsource: product=aws service=cloudtrail · 7a4409fc-f8ca-45f6-8006-127d779eaad9
Detects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB). This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.
Techniques: T1190
Author: Florian Roth (Nextron Systems) · 2021-12-08 (modified 2023-01-02) · logsource: category=webserver · 7b72b328-5708-414f-9a2a-6a6867c26e16
Detects a successful Grafana path traversal exploitation
Techniques: T1190
CVE tags: CVE-2021-43798
Author: NVISO · 2020-02-27 (modified 2023-01-02) · logsource: category=webserver · 7c64e577-d72e-4c3d-9d75-8de6d1f9146a
Detects CVE-2020-0688 Exploitation attempts
Techniques: T1190
CVE tags: CVE-2020-0688
Author: frack113 · 2021-10-06 (modified 2023-01-02) · logsource: category=webserver · 7cb02516-6d95-4ffc-8eee-162075e111ac
When IIS uses an old .Net Framework it's possible to enumerate folders with the symbol "~"
Techniques: T1190
Author: Florian Roth (Nextron Systems) · 2021-11-22 (modified 2022-07-12) · logsource: product=windows service=application · 7dbb86de-a0cc-494c-8aa8-b2996c9ef3c8
Detects PoC tool used to exploit LPE vulnerability CVE-2021-41379
Techniques: T1190
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-06-03 · logsource: product=linux category=process_creation · 7fb14105-530e-4e2e-8cfb-99f7d8700b66
Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2022-26134
Techniques: T1190T1059
CVE tags: CVE-2022-26134
Author: Thomas Patzke, Florian Roth (Nextron Systems), Zach Stanford @svch0st, Tim Shelton, Nasreddine Bencherchali (Nextron Systems) · 2019-01-16 (modified 2024-11-26) · logsource: product=windows category=process_creation · 8202070f-edeb-4d31-a010-a26c72ac5600
Detects potentially suspicious processes being spawned by a web server process which could be the result of a successfully placed web shell or exploitation
Techniques: T1505.003T1190
Author: Florian Roth (Nextron Systems) · 2020-03-25 (modified 2023-01-21) · logsource: product=windows category=process_creation · 846b866e-2a57-46ee-8e16-85fa92759be7
Detects the exploitation of Zoho ManageEngine Desktop Central Java Deserialization vulnerability reported as CVE-2020-10189
CVE tags: CVE-2020-10189
Author: Nasreddine Bencherchali (Nextron Systems), Thurein Oo · 2023-11-08 · logsource: category=webserver · 85254a62-22be-4239-b79c-2ec17e566c37
Detects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which allows the execution of commands on the BIG-IP
Techniques: T1190
Author: Florian Roth (Nextron Systems) · 2020-11-02 (modified 2023-01-02) · logsource: category=webserver · 85d466b0-d74c-4514-84d3-2bdd3327588b
Detects exploitation attempts on WebLogic servers
Techniques: T1190
CVE tags: CVE-2020-14882
Author: FPT.EagleEye Team, wagga · 2020-12-11 (modified 2023-05-04) · logsource: product=windows category=process_creation · 869b9ca7-9ea2-4a5a-8325-e80e62f75445
Detects suspicious child processes of the SQLServer process. This could indicate potential RCE or SQL Injection.
Techniques: T1505.003T1190
Author: Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-04-28 · logsource: product=windows category=file_event · 86a7c91f-98c3-4f14-a58d-d989421e1234
Detects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
Techniques: T1190T1059.003
CVE tags: CVE-2025-31324
Author: Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT) · 2023-11-28 · logsource: category=webserver · 87c83d8e-5390-44ce-aa4a-d3b37e54d0a0
Detects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs.
Techniques: T1190
CVE tags: CVE-2023-4966
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-10-20 · logsource: product=windows category=file_event · 89c42960-f244-4dad-9151-ae9b1a3287a2
Detects suspicious file writes to the root directory of web applications, particularly Apache web servers or Tomcat servers. This may indicate an attempt to deploy malicious files such as web shells or other unauthorized scripts.
Techniques: T1505.003T1190
Author: Bjoern Kimminich · 2017-11-27 (modified 2023-02-12) · logsource: product=sql category=application · 8a670c6d-7189-4b1c-8017-a417ca84a086
Detects SQL error messages that indicate probing for an injection attack
Techniques: T1190
Author: Florian Roth (Nextron Systems) · 2023-06-09 · logsource: product=linux service=sshd · 8b244735-5833-4517-a45b-28d8c63924c0
Detects potential exploitation attempt of CVE-2023-2283 an authentication bypass in libSSH. The exploitation method causes an error message stating that keys for curve25519 could not be generated. It is an error message that is a sign of an exploitation attempt. It is not a sign of a successful exploitation.
Techniques: T1190
CVE tags: CVE-2023-2283
Author: Huntress Team, Swachchhanda Shrawan Poudel (Nextron Systems) · 2026-02-11 · logsource: product=windows category=process_creation · 8c7f4a2d-3b9e-4f1c-9a6d-2e8f5c3d9a1b
Detects suspicious child processes spawned by SolarWinds WebHelpDesk (WHD) application, which may indicate exploitation activity leveraging RCE vulnerabilities such as CVE-2025-40551, CVE-2025-40536, or CVE-2025-26399
Techniques: T1190
CVE tags: CVE-2025-26399CVE-2025-40536CVE-2025-40551
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-12-22 (modified 2023-01-02) · logsource: category=webserver · 92d78c63-5a5c-4c40-9b60-463810ffb082
Detects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint
Techniques: T1190
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-05-14 · logsource: category=webserver · 94e12f41-6cb3-45c5-97b1-c783a7bf2e72
Detects potential command execution via webshell in SAP NetViewer through JSP files with cmd parameter. This rule is created to detect exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution via a webshell.
Techniques: T1505.003T1190
CVE tags: CVE-2025-31324
Author: Moti Harmats · 2023-02-11 · logsource: product=nodejs category=application · 97661d9d-2beb-4630-b423-68985291a8af
Detects process execution related errors in NodeJS. If the exceptions are caused due to user input then they may suggest an RCE vulnerability.
Techniques: T1190
Author: Florian Roth (Nextron Systems) · 2021-12-10 (modified 2023-01-02) · logsource: category=webserver · 9be472ed-893c-4ec0-94da-312d2765f654
Detects exploitation attempt against log4j RCE vulnerability reported as CVE-2021-44228 in different header fields found in web server logs (Log4Shell)
Techniques: T1190
CVE tags: CVE-2021-44228
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-07-19 (modified 2023-01-02) · logsource: category=webserver · a133193c-2daa-4a29-8022-018695fcf0ae
Detects attempts to exploit a Rejetto HTTP File Server (HFS) via CVE-2014-6287
Techniques: T1190T1505.003
CVE tags: CVE-2014-6287
Author: Florian Roth (Nextron Systems) · 2021-05-14 (modified 2023-01-02) · logsource: category=webserver · a2a9d722-0acb-4096-bccc-daaf91a5037b
Detects successful exploitation of Exchange vulnerability as reported in CVE-2021-28480
Techniques: T1190
CVE tags: CVE-2021-28480
Author: Nasreddine Bencherchali (Nextron Systems), Thurein Oo · 2023-10-20 (modified 2023-10-30) · logsource: category=webserver · a2bcca38-9f3a-4d5e-b603-0c587e8569d7
Detects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in access logs.
Techniques: T1190
CVE tags: CVE-2023-43621
Author: Bhabesh Raj · 2020-12-08 (modified 2023-01-02) · logsource: category=webserver · a2e97350-4285-43f2-a63f-d0daff291738
Detects CVE-2018-13379 exploitation attempt against Fortinet SSL VPNs
Techniques: T1190
CVE tags: CVE-2018-13379
Author: Subhash Popuri (@pbssubhash) · 2021-08-25 (modified 2023-01-02) · logsource: category=webserver · a4a899e8-fd7a-49dd-b5a8-7044def72d61
MODx manager - Local File Inclusion:Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter.
Techniques: T1190
CVE tags: CVE-2010-5278
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-11-28 · logsource: category=webserver · a4e068b5-e27c-4f21-85b3-e69e5a4f7ce1
Detects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs by looking for a very long host header string.
Techniques: T1190
CVE tags: CVE-2023-4966
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2026-07-19 · logsource: category=webserver · a7c4e2f9-1b38-4d5c-9e72-3f4a5b6c7d8e
Detects the hardcoded "wp2shell" User-Agent string used by the wp2shell PoC tool during all phases of CVE-2026-63030 and CVE-2026-60137 exploitation.
Techniques: T1190
CVE tags: CVE-2026-63030CVE-2026-60137
Author: Florian Roth (Nextron Systems) · 2022-04-13 (modified 2023-02-03) · logsource: product=windows category=process_creation · a7cd7306-df8b-4398-b711-6f3e4935cf16
Detects suspicious remote procedure call (RPC) service anomalies based on the spawned sub processes (long shot to detect the exploitation of vulnerabilities like CVE-2022-26809)
Techniques: T1190T1569.002
CVE tags: CVE-2022-26809
Author: Andreas Braathen (mnemonic.io) · 2023-11-14 · logsource: category=webserver · a902d249-9b9c-4dc4-8fd0-fbe528ef965c
Detects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
Techniques: T1190
CVE tags: CVE-2023-22518
Author: Nate Guagenti (neu5ron) · 2021-09-20 (modified 2025-11-03) · logsource: product=zeek service=http · ab6b1a39-a9ee-4ab4-b075-e83acf6e346b
Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request. Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP). Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
CVE tags: CVE-2021-38647
Author: Florian Roth (Nextron Systems) · 2021-01-07 (modified 2023-01-02) · logsource: category=webserver · aba47adc-4847-4970-95c1-61dce62a8b29
Detects exploitation attempts on Cisco ASA FTD systems exploiting CVE-2020-3452 with a status code of 200 (sccessful exploitation)
Techniques: T1190
CVE tags: CVE-2020-3452
Author: Arnim Rupp, Florian Roth · 2020-01-02 (modified 2023-01-02) · logsource: category=webserver · ac5a6409-8c89-44c2-8d64-668c29a2d756
Detects CVE-2019-19781 exploitation attempt against Citrix Netscaler, Application Delivery Controller and Citrix Gateway Attack
Techniques: T1190
CVE tags: CVE-2019-19781
Author: Thomas Patzke · 2017-08-06 (modified 2020-09-01) · logsource: product=spring category=application · ae48ab93-45f7-4051-9dfe-5d30a3f78e33
Detects suspicious Spring framework exceptions that could indicate exploitation attempts
Techniques: T1190
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-11-28 · logsource: category=proxy · aee7681f-b53d-4594-a9de-ac51e6ad3362
Detects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs by looking for a very long host header string.
Techniques: T1190
CVE tags: CVE-2023-4966
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · af1ac430-df6b-4b38-b976-0b52f07a0252
Detects instances where an HTTP service on an OpenCanary node has had login attempt via Form POST.
Techniques: T1190
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · af6c3078-84cd-4c68-8842-08b76bd81b13
Detects instances where an HTTP service on an OpenCanary node has received a GET request.
Techniques: T1190
Author: Florian Roth (Nextron Systems), Matt Kelly (list of domains) · 2022-06-07 (modified 2026-07-23) · logsource: category=dns · aff715fa-4dd5-497a-8db3-910bea555566
Detects DNS queries to well-known out-of-band application security testing (OAST) and callback domains. These services (e.g. Burp Collaborator, interactsh, canarytokens, dnslog.cn) are used by security researchers and attackers alike to confirm blind vulnerabilities such as SSRF, XXE, blind RCE, and Log4Shell-style injections, where the exploit payload triggers an external DNS lookup to a controlled domain. A detection indicates that a host on your network resolved one of these domains, which may mean: (1) an attacker is actively probing or exploiting a vulnerable service and using the callback to confirm code execution or data exfiltration, (2) a security scanner (e.g. Nuclei, Gobies) is running against internal targets. Investigate the source host, the full DNS query string (the unique subdomain prefix encodes the callback session), and any concurrent outbound connections or process activity to determine intent.
Techniques: T1190T1595.002
Author: Sittikorn S · 2021-09-24 (modified 2023-01-02) · logsource: category=webserver · b014ea07-8ea0-4859-b517-50a4e5b7ecec
Detects exploitation attempts using file upload vulnerability CVE-2021-22005 in the VMWare vCenter Server.
Techniques: T1190
CVE tags: CVE-2021-22005
Author: Jason Rathbun (Blackpoint Cyber) · 2024-02-26 · logsource: product=windows category=process_creation · b19146a3-25d4-41b4-928b-1e2a92641b1b
Detects potential web shell execution from the ScreenConnect server process.
Techniques: T1190
Author: Florian Roth (Nextron Systems) · 2020-07-15 (modified 2022-07-12) · logsource: product=windows category=process_creation · b5281f31-f9cc-4d0d-95d0-45b91c45b487
Detects exploitation of DNS RCE bug reported in CVE-2020-1350 by the detection of suspicious sub process
Techniques: T1190T1569.002
CVE tags: CVE-2020-1350
Author: Nasreddine Bencherchali (Nextron Systems), Thurein Oo · 2023-11-08 · logsource: category=proxy · b59c98c6-95e8-4d65-93ee-f594dfb96b17
Detects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which allows the execution of commands on the BIG-IP
Techniques: T1190
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2026-07-19 · logsource: category=webserver · b8d5f301-2c49-4e6d-af83-4a5b6c7d8e9f
Detects exploitation attempts against the WordPress REST batch endpoint (CVE-2026-63030, CVE-2026-60137) using the wp2shell PoC tool. The tool sends POST requests to the batch endpoint via the ?rest_route=/batch/v1 query parameter, covering all attack phases from initial probe through SQL injection and pre-auth admin creation. A 207 response confirms the endpoint is active on the target.
Techniques: T1190
CVE tags: CVE-2026-63030CVE-2026-60137
Author: Florian Roth (Nextron Systems) · 2021-05-22 (modified 2023-01-02) · logsource: category=webserver · b9888738-29ed-4c54-96a4-f38c57b84bb3
Detects the exploitation of the Wazuh RCE vulnerability described in CVE-2021-26814
Techniques: T1190
CVE tags: CVE-2021-21978CVE-2021-26814
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-07-21 (modified 2025-07-24) · logsource: product=windows category=file_event · ba479447-721f-42a9-9af2-6dcd517bbdb3
Detects the creation of file such as spinstall0.aspx which may indicate successful exploitation of CVE-2025-53770. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
Techniques: T1190
CVE tags: CVE-2025-53770
Author: Moti Harmats · 2023-02-11 · logsource: product=jvm category=application · bb0e9cec-d4da-46f5-997f-22efc59f3dca
Detects potential JNDI Injection exploitation. Often coupled with Log4Shell exploitation.
Techniques: T1190
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) · 2023-06-01 (modified 2024-08-13) · logsource: product=windows category=file_event · c3b2a774-3152-4989-83c1-7afc48fd1599
Detects file indicators of potential exploitation of MOVEit CVE-2023-34362.
Techniques: T1190
CVE tags: CVE-2023-34362
Author: Florian Roth (Nextron Systems) · 2017-07-08 (modified 2022-07-07) · logsource: category=proxy · c42a3073-30fb-48ae-8c99-c23ada84b103
Detects suspicious user agent strings user by hack tools in proxy logs
Techniques: T1190T1110
Author: Moti Harmats · 2023-02-11 · logsource: product=jvm category=application · c4e06896-e27c-4583-95ac-91ce2279345d
Detects XML parsing issues, if the application expects to work with XML make sure that the parser is initialized safely.
Techniques: T1190
Author: Swachchhanda Shrawan Poudel (Nextron Systems), Nasreddine Bencherchali · 2025-12-05 · logsource: product=linux category=process_creation · c70834fa-fb9d-4aa0-9e7d-45ceed36f3f7
Detects suspicious child processes spawned from Node.js server processes on Linux systems, potentially indicating remote code execution exploitation such as CVE-2025-55182 (React2Shell). This rule particularly looks for exploitation of vulnerability on Node.js Servers where attackers abuse Node.js child_process module to execute arbitrary system commands. When execSync() or exec() is used, the command line often includes a shell invocation followed by suspicious commands or scripts (e.g., /bin/sh -c <malicious-command>). For other methods, the Image field will show the spawned process directly.
Techniques: T1059T1190
CVE tags: CVE-2025-55182
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-07-20 · logsource: product=linux category=process_creation · c8a5f584-cdc8-42cc-8cce-0398e4265de3
Detects attempts to exploit an apache spark server via CVE-2014-6287 from a commandline perspective
Techniques: T1190
CVE tags: CVE-2022-33891
Author: Florian Roth (Nextron Systems) · 2018-02-20 (modified 2022-10-05) · logsource: product=linux service=syslog · c8e35e96-19ce-4f16-aeb6-fd5588dc5365
Detects suspicious DNS error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
Techniques: T1190
Author: Isa Almannaei · 2023-02-13 · logsource: category=webserver · d033cb8a-8669-4a8e-a974-48d4185a8503
Detects potential exploitation attempts of CVE-2022-21587 an arbitrary file upload vulnerability impacting Oracle E-Business Suite (EBS). CVE-2022-21587 can lead to unauthenticated remote code execution.
Techniques: T1190
CVE tags: CVE-2022-21587
Author: Florian Roth (Nextron Systems), wagga · 2020-02-29 (modified 2022-12-25) · logsource: product=windows service=application · d6266bf5-935e-4661-b477-78772735a7cb
Detects the exploitation of Microsoft Exchange vulnerability as described in CVE-2020-0688
Techniques: T1190
CVE tags: CVE-2020-0688
Author: Moti Harmats · 2023-02-11 · logsource: product=jvm category=application · d65f37da-a26a-48f8-8159-3dde96680ad2
Detects process execution related exceptions in JVM based apps, often relates to RCE
Techniques: T1190
Author: @juju4 · 2022-12-27 · logsource: category=database · d84c0ded-edd7-4123-80ed-348bb3ccc4d5
Detects suspicious SQL query keywrods that are often used during recon, exfiltration or destructive activities. Such as dropping tables and selecting wildcard fields
Techniques: T1190T1505.001
Author: @gott_cyber · 2022-08-17 (modified 2023-01-02) · logsource: category=webserver · dd218fb6-4d02-42dc-85f0-a0a376072efd
Detects an attempt to leverage the vulnerable servlet "mboximport" for an unauthenticated remote command injection
Techniques: T1190
CVE tags: CVE-2022-27925
Author: Moti Harmats · 2023-02-11 · logsource: product=jvm category=application · e032f5bc-4563-4096-ae3b-064bab588685
Detects potential local file read vulnerability in JVM based apps. If the exceptions are caused due to user input and contain path traversal payloads then it's a red flag.
Techniques: T1190
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-10-31 · logsource: product=windows service=application · e5f66e87-7d6b-404f-92fe-7aa67814b5cd
Detects cast exceptions in Windows Server Update Services (WSUS) application logs that highly indicate exploitation attempts of CVE-2025-59287, a deserialization vulnerability in WSUS.
Techniques: T1190T1203
CVE tags: CVE-2025-59287
Author: Florian Roth (Nextron Systems) · 2017-06-30 (modified 2021-11-27) · logsource: product=linux service=sshd · e76b413a-83d0-4b94-8e4c-85db4a5b8bdc
Detects suspicious SSH / SSHD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
Techniques: T1190
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-11-08 · logsource: category=webserver · e9928831-ba14-42ea-a4bc-33d352b9929a
Detects exploitation activity of CVE-2023-46747 an unauthenticated remote code execution vulnerability in F5 BIG-IP.
Techniques: T1190
CVE tags: CVE-2023-46747
Author: Florian Roth (Nextron Systems) · 2019-01-22 (modified 2021-11-27) · logsource: service=apache · e9a2b582-3f6a-48ac-b4a1-6849cdc50b3c
Detects an issue in apache logs that reports threading related errors
Techniques: T1190T1210
Author: Florian Roth (Nextron Systems) · 2020-05-26 (modified 2023-01-02) · logsource: category=webserver · e9bc39ae-978a-4e49-91ab-5bd481fc668b
Detects the exploitation of the Confluence vulnerability described in CVE-2019-3398
Techniques: T1190
CVE tags: CVE-2019-3398
Author: Moti Harmats · 2023-02-11 · logsource: product=spring category=application · e9edd087-89d8-48c9-b0b4-5b9bb10896b8
Detects potential SpEL Injection exploitation, which may lead to RCE.
Techniques: T1190
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-12 (modified 2023-01-02) · logsource: category=webserver · efdb2003-a922-48aa-8f37-8b80021a9706
Detects possible exploitation of VMware Workspace ONE Access Admin Remote Code Execution vulnerability as described in CVE-2022-31659
Techniques: T1190
CVE tags: CVE-2022-31659
Author: frack113 · 2021-08-10 (modified 2023-05-08) · logsource: category=webserver · effee1f6-a932-4297-a81f-acb44064fa3a
When exploiting this vulnerability with CVE-2021-26858, an SSRF attack is used to manipulate virtual directories
Techniques: T1190
CVE tags: CVE-2021-26858
Author: Tanner Filip, Austin Worline, Chad Hudson, Matt Anderson · 2024-12-09 · logsource: product=windows category=process_creation · f007b877-02e3-45b7-8501-1b78c2864029
Detects exploitation attempt of Cleo's CVE-2024-50623 by looking for a "cmd.exe" process spawning from the Celo software suite with suspicious Powershell commandline.
Techniques: T1190
CVE tags: CVE-2024-50623
Author: Bhabesh Raj · 2021-08-24 (modified 2023-01-02) · logsource: category=webserver · f0500377-bc70-425d-ac8c-e956cd906871
Detects exploitation of vulnerabilities in Arcadyan routers as reported in CVE-2021-20090 and CVE-2021-20091.
Techniques: T1190
CVE tags: CVE-2021-20090CVE-2021-20091
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-11-08 · logsource: category=proxy · f195b2ff-e542-41bf-8d91-864fb81e5c20
Detects exploitation activity of CVE-2023-46747 an unauthenticated remote code execution vulnerability in F5 BIG-IP.
Techniques: T1190
CVE tags: CVE-2023-46747
Author: Bhabesh Raj, Florian Roth · 2021-08-19 (modified 2023-01-02) · logsource: category=webserver · f425637f-891c-4191-a6c4-3bb1b70513b4
Detects CVE-2021-22123 exploitation attempt against Fortinet WAFs
Techniques: T1190
CVE tags: CVE-2021-22123
Author: Nasreddine Bencherchali (Nextron Systems), Thurein Oo · 2023-10-20 (modified 2023-10-30) · logsource: category=proxy · f48f5368-355c-4a1b-8bf5-11c13d589eaa
Detects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in proxy logs.
Techniques: T1190
CVE tags: CVE-2023-43621
Author: NVISO · 2020-05-06 (modified 2024-03-11) · logsource: product=windows service=security · f88e112a-21aa-44bd-9b01-6ee2a2bbbed1
Detects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.
Techniques: T1078T1190T1133
Author: Andreas Braathen (mnemonic.io) · 2023-11-14 · logsource: product=linux category=process_creation · f8987c03-4290-4c96-870f-55e75ee377f4
Detects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
Techniques: T1059T1190
CVE tags: CVE-2023-22518
Author: Sittikorn S, Nuttakorn Tungpoonsup · 2021-09-10 (modified 2023-01-02) · logsource: category=webserver · fcbb4a77-f368-4945-b046-4499a1da69d1
Detects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).
Techniques: T1190T1505.003
CVE tags: CVE-2021-40539
Author: Florian Roth (Nextron Systems) · 2020-02-29 (modified 2023-01-02) · logsource: category=webserver · fce2c2e2-0fb5-41ab-a14c-5391e1fd70a5
Detects the exploitation of Microsoft Exchange vulnerability as described in CVE-2020-0688
Techniques: T1190
CVE tags: CVE-2020-0688
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-08-12 (modified 2023-01-02) · logsource: category=webserver · fcf1101d-07c9-49b2-ad81-7e421ff96d80
Detects the exploitation of VMware Workspace ONE Access Authentication Bypass vulnerability as described in CVE-2022-31656 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Techniques: T1190
CVE tags: CVE-2022-31656
Author: Thomas Patzke · 2017-08-05 (modified 2020-09-01) · logsource: product=django category=application · fd435618-981e-4a7c-81f8-f78ce480d616
Detects suspicious Django web application framework exceptions that could indicate exploitation attempts
Techniques: T1190
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-12-22 · logsource: category=proxy · fdd7e904-7304-4616-a46a-e32f917c4be4
Detects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint
Techniques: T1190
Author: X__Junior (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-10-20 · logsource: product=windows category=process_creation · ff0225a0-1d9a-4bae-ab26-6038b18bb6d4
Detects the use of argument injection in the Commvault qlogin command - potential exploitation for CVE-2025-57791. An attacker can inject the `-localadmin` parameter via the password field to bypass authentication and gain a privileged token.
Techniques: T1190
CVE tags: CVE-2025-57791
Author: Nasreddine Bencherchali (Nextron Systems), Michael Haag (STRT) · 2023-11-28 · logsource: category=proxy · ff349b81-617f-4af4-924f-dbe8ea9bab41
Detects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs.
Techniques: T1190
CVE tags: CVE-2023-4966