MITRE ATT&CK technique
Exploit Public-Facing Application detection rulesT1190
Exploit Public-Facing Application (T1190) is a MITRE ATT&CK technique in the Initial Access tactic. This page lists the 149 community-maintained Sigma detection rules in the library mapped to T1190 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux, jvm.
Tactic
Arcadyan Router Exploitations
criticalDetects exploitation of vulnerabilities in Arcadyan routers as reported in CVE-2021-20090 and CVE-2021-20091.
webserver
Citrix ADS Exploitation CVE-2020-8193 CVE-2020-8195
criticalDetects exploitation attempt against Citrix Netscaler, Application Delivery Controller (ADS) and Citrix Gateway exploiting vulnerabilities reported as CVE-2020-8193 and CVE-2020-8195
webserver
Citrix Netscaler Attack CVE-2019-19781
criticalDetects CVE-2019-19781 exploitation attempt against Citrix Netscaler, Application Delivery Controller and Citrix Gateway Attack
webserver
Confluence Exploitation CVE-2019-3398
criticalDetects the exploitation of the Confluence vulnerability described in CVE-2019-3398
webserver
CVE-2010-5278 Exploitation Attempt
criticalMODx manager - Local File Inclusion:Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter.
webserver
CVE-2020-0688 Exchange Exploitation via Web Log
criticalDetects the exploitation of Microsoft Exchange vulnerability as described in CVE-2020-0688
webserver
CVE-2020-10148 SolarWinds Orion API Auth Bypass
criticalDetects CVE-2020-10148 SolarWinds Orion API authentication bypass attempts
webserver
CVE-2020-5902 F5 BIG-IP Exploitation Attempt
criticalDetects the exploitation attempt of the vulnerability found in F5 BIG-IP and described in CVE-2020-5902
webserver
CVE-2021-33766 Exchange ProxyToken Exploitation
criticalDetects the exploitation of Microsoft Exchange ProxyToken vulnerability as described in CVE-2021-33766
webserver
CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
criticalDetects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).
webserver
DNS RCE CVE-2020-1350
criticalDetects exploitation of DNS RCE bug reported in CVE-2020-1350 by the detection of suspicious sub process
windows · process_creation
Exchange Exploitation CVE-2021-28480
criticalDetects successful exploitation of Exchange vulnerability as reported in CVE-2021-28480
webserver
Fortinet CVE-2018-13379 Exploitation
criticalDetects CVE-2018-13379 exploitation attempt against Fortinet SSL VPNs
webserver
Fortinet CVE-2021-22123 Exploitation
criticalDetects CVE-2021-22123 exploitation attempt against Fortinet WAFs
webserver
Grafana Path Traversal Exploitation CVE-2021-43798
criticalDetects a successful Grafana path traversal exploitation
webserver
Oracle WebLogic Exploit
criticalDetects access to a webshell dropped into a keystore folder on the WebLogic server
webserver
Oracle WebLogic Exploit CVE-2021-2109
criticalDetects the exploitation of the WebLogic server vulnerability described in CVE-2021-2109
webserver
OWASSRF Exploitation Attempt Using Public POC - Proxy
criticalDetects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint
proxy
OWASSRF Exploitation Attempt Using Public POC - Webserver
criticalDetects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint
webserver
Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create
criticalDetects the creation of file such as spinstall0.aspx which may indicate successful exploitation of CVE-2025-53770. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
windows · file_event
ProxyLogon Reset Virtual Directories Based On IIS Log
criticalWhen exploiting this vulnerability with CVE-2021-26858, an SSRF attack is used to manipulate virtual directories
webserver
Pulse Secure Attack CVE-2019-11510
criticalDetects CVE-2019-11510 exploitation attempt - URI contains Guacamole
webserver
ADSelfService Exploitation
highDetects suspicious access to URLs that was noticed in cases in which attackers exploitated the ADSelfService vulnerability CVE-2021-40539
webserver
Apache Spark Shell Command Injection - ProcessCreation
highDetects attempts to exploit an apache spark server via CVE-2014-6287 from a commandline perspective
linux · process_creation
Apache Spark Shell Command Injection - Weblogs
highDetects attempts to exploit an apache spark server via CVE-2014-6287 from a weblogs perspective
webserver
Atlassian Bitbucket Command Injection Via Archive API
highDetects attempts to exploit the Atlassian Bitbucket Command Injection CVE-2022-36804
webserver
Atlassian Confluence CVE-2022-26134
highDetects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2022-26134
linux · process_creation
Cisco ASA Exploitation Activity - Proxy
highDetects suspicious requests to Cisco ASA WebVpn via proxy logs associated with CVE-2025-20333 and CVE-2025-20362 exploitation.
proxy
Cisco ASA FTD Exploit CVE-2020-3452
highDetects exploitation attempts on Cisco ASA FTD systems exploiting CVE-2020-3452 with a status code of 200 (sccessful exploitation)
webserver
Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791)
highDetects the use of argument injection in the Commvault qlogin command - potential exploitation for CVE-2025-57791. An attacker can inject the `-localadmin` parameter via the password field to bypass authentication and gain a privileged token.
windows · process_creation
CVE-2020-0688 Exploitation Attempt
highDetects CVE-2020-0688 Exploitation attempts
webserver
CVE-2020-0688 Exploitation via Eventlog
highDetects the exploitation of Microsoft Exchange vulnerability as described in CVE-2020-0688
windows
CVE-2021-21972 VSphere Exploitation
highDetects the exploitation of VSphere Remote Code Execution vulnerability as described in CVE-2021-21972
webserver
CVE-2021-21978 Exploitation Attempt
highDetects the exploitation of the VMware View Planner vulnerability described in CVE-2021-21978
webserver
CVE-2021-41773 Exploitation Attempt
highDetects exploitation of flaw in path normalization in Apache HTTP server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the expected document root. If files outside of the document root are not protected by "require all denied" these requests can succeed. Additionally this flaw could leak the source of interpreted files like CGI scripts. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions.
webserver
CVE-2022-31656 VMware Workspace ONE Access Auth Bypass
highDetects the exploitation of VMware Workspace ONE Access Authentication Bypass vulnerability as described in CVE-2022-31656 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
webserver
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux)
highDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
linux · process_creation
CVE-2023-46747 Exploitation Activity - Proxy
highDetects exploitation activity of CVE-2023-46747 an unauthenticated remote code execution vulnerability in F5 BIG-IP.
proxy
CVE-2023-46747 Exploitation Activity - Webserver
highDetects exploitation activity of CVE-2023-46747 an unauthenticated remote code execution vulnerability in F5 BIG-IP.
webserver
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
highDetects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs by looking for a very long host header string.
proxy
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
highDetects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs by looking for a very long host header string.
webserver
CVE-2024-50623 Exploitation Attempt - Cleo
highDetects exploitation attempt of Cleo's CVE-2024-50623 by looking for a "cmd.exe" process spawning from the Celo software suite with suspicious Powershell commandline.
windows · process_creation
DNS Query to External Service Interaction Domains
highDetects DNS queries to well-known out-of-band application security testing (OAST) and callback domains. These services (e.g. Burp Collaborator, interactsh, canarytokens, dnslog.cn) are used by security researchers and attackers alike to confirm blind vulnerabilities such as SSRF, XXE, blind RCE, and Log4Shell-style injections, where the exploit payload triggers an external DNS lookup to a controlled domain. A detection indicates that a host on your network resolved one of these domains, which may mean: (1) an attacker is actively probing or exploiting a vulnerable service and using the callback to confirm code execution or data exfiltration, (2) a security scanner (e.g. Nuclei, Gobies) is running against internal targets. Investigate the source host, the full DNS query string (the unique subdomain prefix encodes the callback session), and any concurrent outbound connections or process activity to determine intent.
dns
Exchange Exploitation Used by HAFNIUM
highDetects exploitation attempts in Exchange server logs as described in blog posts reporting on HAFNIUM group activity
webserver
Exchange ProxyShell Pattern
highDetects URL patterns that could be found in ProxyShell exploitation attempts against Exchange servers (failed and successful)
webserver
Exploitation Activity of CVE-2025-59287 - WSUS Deserialization
highDetects cast exceptions in Windows Server Update Services (WSUS) application logs that highly indicate exploitation attempts of CVE-2025-59287, a deserialization vulnerability in WSUS.
windows
Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
highDetects the creation of command-line interpreters (cmd.exe, powershell.exe) as child processes of Windows Server Update Services (WSUS) related process wsusservice.exe. This behavior is a key indicator of exploitation for the critical remote code execution vulnerability such as CVE-2025-59287, where attackers spawn shells to conduct reconnaissance and further post-exploitation activities.
windows · process_creation
Exploitation of CVE-2021-26814 in Wazuh
highDetects the exploitation of the Wazuh RCE vulnerability described in CVE-2021-26814
webserver
Exploited CVE-2020-10189 Zoho ManageEngine
highDetects the exploitation of Zoho ManageEngine Desktop Central Java Deserialization vulnerability reported as CVE-2020-10189
windows · process_creation
Hack Tool User Agent
highDetects suspicious user agent strings user by hack tools in proxy logs
proxy
Java Payload Strings
highDetects possible Java payloads in web access logs
webserver
JNDIExploit Pattern
highDetects exploitation attempt using the JNDI-Exploit-Kit
webserver
Linux Suspicious Child Process from Node.js - React2Shell
highDetects suspicious child processes spawned from Node.js server processes on Linux systems, potentially indicating remote code execution exploitation such as CVE-2025-55182 (React2Shell). This rule particularly looks for exploitation of vulnerability on Node.js Servers where attackers abuse Node.js child_process module to execute arbitrary system commands. When execSync() or exec() is used, the command line often includes a shell invocation followed by suspicious commands or scripts (e.g., /bin/sh -c <malicious-command>). For other methods, the Image field will show the spawned process directly.
linux · process_creation
Log4j RCE CVE-2021-44228 Generic
highDetects exploitation attempt against log4j RCE vulnerability reported as CVE-2021-44228 (Log4Shell)
webserver
Log4j RCE CVE-2021-44228 in Fields
highDetects exploitation attempt against log4j RCE vulnerability reported as CVE-2021-44228 in different header fields found in web server logs (Log4Shell)
webserver
LPE InstallerFileTakeOver PoC CVE-2021-41379
highDetects PoC tool used to exploit LPE vulnerability CVE-2021-41379
windows
OMIGOD HTTP No Authentication RCE - CVE-2021-38647
highDetects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request. Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP). Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
zeek
OMIGOD SCX RunAsProvider ExecuteScript
highRule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell. Script being executed gets created as a temp file in /tmp folder with a scx* prefix. Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/. The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
linux · process_creation
OMIGOD SCX RunAsProvider ExecuteShellCommand
highRule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
linux · process_creation
OpenCanary - FTP Login Attempt
highDetects instances where an FTP service on an OpenCanary node has had a login attempt.
opencanary · application
OpenCanary - HTTP GET Request
highDetects instances where an HTTP service on an OpenCanary node has received a GET request.
opencanary · application
OpenCanary - HTTP POST Login Attempt
highDetects instances where an HTTP service on an OpenCanary node has had login attempt via Form POST.
opencanary · application
Oracle WebLogic Exploit CVE-2020-14882
highDetects exploitation attempts on WebLogic servers
webserver
Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
highDetects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084
windows · process_creation
Potential Centos Web Panel Exploitation Attempt - CVE-2022-44877
highDetects potential exploitation attempts that target the Centos Web Panel 7 Unauthenticated Remote Code Execution CVE-2022-44877
webserver
Potential CVE-2021-26084 Exploitation Attempt
highDetects potential exploitation of CVE-2021-260841 a Confluence RCE using OGNL injection
webserver
Potential CVE-2021-44228 Exploitation Attempt - VMware Horizon
highDetects potential initial exploitation attempts against VMware Horizon deployments running a vulnerable versions of Log4j.
windows · process_creation
Potential CVE-2022-21587 Exploitation Attempt
highDetects potential exploitation attempts of CVE-2022-21587 an arbitrary file upload vulnerability impacting Oracle E-Business Suite (EBS). CVE-2022-21587 can lead to unauthenticated remote code execution.
webserver
Potential CVE-2022-26809 Exploitation Attempt
highDetects suspicious remote procedure call (RPC) service anomalies based on the spawned sub processes (long shot to detect the exploitation of vulnerabilities like CVE-2022-26809)
windows · process_creation
Potential CVE-2022-46169 Exploitation Attempt
highDetects potential exploitation attempts that target the Cacti Command Injection CVE-2022-46169
webserver
Potential CVE-2023-23752 Exploitation Attempt
highDetects the potential exploitation attempt of CVE-2023-23752 an Improper access check, in web service endpoints in Joomla
webserver
Potential CVE-2023-25717 Exploitation Attempt
highDetects a potential exploitation attempt of CVE-2023-25717 a Remote Code Execution via an unauthenticated HTTP GET Request, in Ruckus Wireless Admin
webserver
Potential Exploitation Attempt Of Undocumented WindowsServer RCE
highDetects potential exploitation attempt of undocumented Windows Server Pre Auth Remote Code Execution (RCE)
windows · process_creation
Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
highDetects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.
windows · process_creation
Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE
highDetects potential exploitation of a chained vulnerability attack targeting Ivanti EPMM 12.5.0.0. CVE-2025-4427 allows unauthenticated access to protected API endpoints via an authentication bypass, which can then be leveraged to trigger CVE-2025-4428 — a remote code execution vulnerability through template injection. This sequence enables unauthenticated remote code execution, significantly increasing the impact of exploitation.
webserver
Potential Exploitation of GoAnywhere MFT Vulnerability
highDetects suspicious command execution by child processes of the GoAnywhere Managed File Transfer (MFT) application, which may indicate exploitation such as CVE-2025-10035. This behavior is indicative of post-exploitation activity related to CVE-2025-10035, as observed in campaigns by the threat actor Storm-1175.
windows · process_creation
Potential Information Disclosure CVE-2023-43261 Exploitation - Proxy
highDetects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in proxy logs.
proxy
Potential Information Disclosure CVE-2023-43261 Exploitation - Web
highDetects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in access logs.
webserver
Potential JNDI Injection Exploitation In JVM Based Application
highDetects potential JNDI Injection exploitation. Often coupled with Log4Shell exploitation.
jvm · application
Potential Local File Read Vulnerability In JVM Based Application
highDetects potential local file read vulnerability in JVM based apps. If the exceptions are caused due to user input and contain path traversal payloads then it's a red flag.
jvm · application
Potential MOVEit Transfer CVE-2023-34362 Exploitation - File Activity
highDetects file indicators of potential exploitation of MOVEit CVE-2023-34362.
windows · file_event
Potential OGNL Injection Exploitation In JVM Based Application
highDetects potential OGNL Injection exploitation, which may lead to RCE. OGNL is an expression language that is supported in many JVM based systems. OGNL Injection is the reason for some high profile RCE's such as Apache Struts (CVE-2017-5638) and Confluence (CVE-2022-26134)
jvm · application
Potential OWASSRF Exploitation Attempt - Proxy
highDetects exploitation attempt of the OWASSRF variant targeting exchange servers It uses the OWA endpoint to access the powershell backend endpoint
proxy
Potential OWASSRF Exploitation Attempt - Webserver
highDetects exploitation attempt of the OWASSRF variant targeting exchange servers It uses the OWA endpoint to access the powershell backend endpoint
webserver
Potential RCE Exploitation Attempt In NodeJS
highDetects process execution related errors in NodeJS. If the exceptions are caused due to user input then they may suggest an RCE vulnerability.
nodejs · application
Potential SAP NetViewer Webshell Command Execution
highDetects potential command execution via webshell in SAP NetViewer through JSP files with cmd parameter. This rule is created to detect exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution via a webshell.
webserver
Potential Server Side Template Injection In Velocity
highDetects exceptions in velocity template renderer, this most likely happens due to dynamic rendering of user input and may lead to RCE.
velocity · application
Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators
highDetects potential exploitation of CVE-2025-53770 by identifying indicators such as suspicious command lines discovered in Post-Exploitation activities. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
windows · process_creation
Potential SpEL Injection In Spring Framework
highDetects potential SpEL Injection exploitation, which may lead to RCE.
spring · application
Potential XXE Exploitation Attempt In JVM Based Application
highDetects XML parsing issues, if the application expects to work with XML make sure that the parser is initialized safely.
jvm · application
Process Execution Error In JVM Based Application
highDetects process execution related exceptions in JVM based apps, often relates to RCE
jvm · application
Pulse Connect Secure RCE Attack CVE-2021-22893
highThis rule detects exploitation attempts using Pulse Connect Secure(PCS) vulnerability (CVE-2021-22893)
webserver
Rejetto HTTP File Server RCE
highDetects attempts to exploit a Rejetto HTTP File Server (HFS) via CVE-2014-6287
webserver
Remote Access Tool - ScreenConnect Server Web Shell Execution
highDetects potential web shell execution from the ScreenConnect server process.
windows · process_creation
Sitecore Pre-Auth RCE CVE-2021-42237
highDetects exploitation attempts of Sitecore Experience Platform Pre-Auth RCE CVE-2021-42237 found in Report.ashx
webserver
SonicWall SSL/VPN Jarrewrite Exploitation
highDetects exploitation attempts of the SonicWall Jarrewrite Exploit
webserver
SQL Injection Strings In URI
highDetects potential SQL injection attempts via GET requests in access logs.
webserver
Suspicious Child Process of SolarWinds WebHelpDesk
highDetects suspicious child processes spawned by SolarWinds WebHelpDesk (WHD) application, which may indicate exploitation activity leveraging RCE vulnerabilities such as CVE-2025-40551, CVE-2025-40536, or CVE-2025-26399
windows · process_creation
Suspicious Child Process Of SQL Server
highDetects suspicious child processes of the SQLServer process. This could indicate potential RCE or SQL Injection.
windows · process_creation
Suspicious File Write to SharePoint Layouts Directory
highDetects suspicious file writes to SharePoint layouts directory which could indicate webshell activity or post-exploitation. This behavior has been observed in the exploitation of SharePoint vulnerabilities such as CVE-2025-49704, CVE-2025-49706 or CVE-2025-53770.
windows · file_event
Suspicious MSExchangeMailboxReplication ASPX Write
highDetects suspicious activity in which the MSExchangeMailboxReplication process writes .asp and .apsx files to disk, which could be a sign of ProxyShell exploitation
windows · file_event
Suspicious Named Error
highDetects suspicious DNS error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
linux
Suspicious Process By Web Server Process
highDetects potentially suspicious processes being spawned by a web server process which could be the result of a successfully placed web shell or exploitation
windows · process_creation
Suspicious Processes Spawned by WinRM
highDetects suspicious processes including shells spawnd from WinRM host process
windows · process_creation
Suspicious SQL Error Messages
highDetects SQL error messages that indicate probing for an injection attack
sql · application
Terminal Service Process Spawn
highDetects a process spawned by the terminal service server process (this could be an indicator for an exploitation of CVE-2019-0708)
windows · process_creation
TerraMaster TOS CVE-2020-28188
highDetects the exploitation of the TerraMaster TOS vulnerability described in CVE-2020-28188
webserver
VMware vCenter Server File Upload CVE-2021-22005
highDetects exploitation attempts using file upload vulnerability CVE-2021-22005 in the VMWare vCenter Server.
webserver
Windows Suspicious Child Process from Node.js - React2Shell
highDetects suspicious child processes started by Node.js server processes on Windows, which may indicate exploitation of vulnerabilities like CVE-2025-55182 (React2Shell). Attackers can abuse the Node.js 'child_process' module to run system commands or scripts using methods such as spawn(), exec(), execFile(), fork(), or execSync(). If execSync() or exec() is used in the exploit, the command line often shows a shell (e.g., cmd.exe /d /s /c ...) running a suspicious command unless other shells are explicitly invoked. For other methods, the spawned process appears directly in the Image field unless a shell is explicitly used.
windows · process_creation
WordPress Wp2shell Exploitation Tool User-Agent
highDetects the hardcoded "wp2shell" User-Agent string used by the wp2shell PoC tool during all phases of CVE-2026-63030 and CVE-2026-60137 exploitation.
webserver
Apache Threading Error
mediumDetects an issue in apache logs that reports threading related errors
CVE-2022-31659 VMware Workspace ONE Access RCE
mediumDetects possible exploitation of VMware Workspace ONE Access Admin Remote Code Execution vulnerability as described in CVE-2022-31659
webserver
CVE-2023-1389 Potential Exploitation Attempt - Unauthenticated Command Injection In TP-Link Archer AX21
mediumDetects potential exploitation attempt of CVE-2023-1389 an Unauthenticated Command Injection in TP-Link Archer AX21.
proxy
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
mediumDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
windows · process_creation
CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy)
mediumDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
proxy
CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Webserver)
mediumDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
webserver
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
mediumDetects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs.
proxy
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
mediumDetects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs.
webserver
Django Framework Exceptions
mediumDetects suspicious Django web application framework exceptions that could indicate exploitation attempts
django · application
F5 BIG-IP iControl Rest API Command Execution - Proxy
mediumDetects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which allows the execution of commands on the BIG-IP
proxy
F5 BIG-IP iControl Rest API Command Execution - Webserver
mediumDetects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which allows the execution of commands on the BIG-IP
webserver
Failed Logon From Public IP
mediumDetects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.
windows
Ingress/Egress Security Group Modification
mediumDetects when an account makes changes to the ingress or egress rules of a security group. This can indicate that an attacker is attempting to open up new attack vectors in the account, that they are trying to exfiltrate data over the network, or that they are trying to allow machines in that VPC/Subnet to contact a C&C server.
aws
LoadBalancer Security Group Modification
mediumDetects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB). This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.
aws
Path Traversal Exploitation Attempts
mediumDetects path traversal exploitation attempts
webserver
Potential CVE-2021-27905 Exploitation Attempt
mediumDetects exploitation attempt of the CVE-2021-27905 which affects all Apache Solr versions prior to and including 8.8.1.
webserver
Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution
mediumDetects potential exploitation attempt of CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access and Identity Manager. As reported by Morphisec, part of the attack chain, threat actors used PowerShell commands that executed as a child processes of the legitimate Tomcat "prunsrv.exe" process application.
windows · process_creation
Potential CVE-2023-2283 Exploitation
mediumDetects potential exploitation attempt of CVE-2023-2283 an authentication bypass in libSSH. The exploitation method causes an error message stating that keys for curve25519 could not be generated. It is an error message that is a sign of an exploitation attempt. It is not a sign of a successful exploitation.
linux
Potential CVE-2023-27997 Exploitation Indicators
mediumDetects indicators of potential exploitation of CVE-2023-27997 in Frotigate weblogs. To avoid false positives it is best to look for successive requests to the endpoints mentioned as well as weird values of the "enc" parameter
webserver
Potential SAP NetWeaver Webshell Creation
mediumDetects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
windows · file_event
Potential SAP NetWeaver Webshell Creation - Linux
mediumDetects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
linux · file_event
Python SQL Exceptions
mediumGeneric rule for SQL exceptions in Python according to PEP 249
python · application
RDS Database Security Group Modification
mediumDetects changes to the security group entries for RDS databases. This can indicate that a misconfiguration has occurred which potentially exposes the database to the public internet, a wider audience within the VPC or that removal of valid rules has occurred which could impact the availability of the database to legitimate services and users.
aws
RedTail Cryptominer User-Agent
mediumDetects inbound web requests using the "libredtail-http" User-Agent. libredtail-http is a unique User-Agent string associated with a campaign of automated, malicious scans and attacks targeting exposed container environments and web applications,notably identified in activities stemming from late 2024 through early 2026. It is primarily used by the RedTail cryptominer malware to identify and exploit vulnerabilities for deploying cryptocurrency miners.
webserver
Ruby on Rails Framework Exceptions
mediumDetects suspicious Ruby on Rails exceptions that could indicate exploitation attempts
ruby_on_rails · application
SharePoint ToolShell CVE-2025-53770 Exploitation - Web IIS
mediumDetects access to vulnerable SharePoint components potentially being exploited in CVE-2025-53770 through IIS web server logs. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
webserver
Spring Framework Exceptions
mediumDetects suspicious Spring framework exceptions that could indicate exploitation attempts
spring · application
Successful IIS Shortname Fuzzing Scan
mediumWhen IIS uses an old .Net Framework it's possible to enumerate folders with the symbol "~"
webserver
Suspicious Child Process of SAP NetWeaver
mediumDetects suspicious child processes spawned by SAP NetWeaver that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
windows · process_creation
Suspicious Child Process of SAP NetWeaver - Linux
mediumDetects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
linux · process_creation
Suspicious CrushFTP Child Process
mediumDetects suspicious child processes spawned by the CrushFTP service that may indicate exploitation of remote code execution vulnerabilities such as CVE-2025-31161, where attackers can achieve RCE through crafted HTTP requests. The detection focuses on commonly abused Windows executables (like powershell.exe, cmd.exe etc.) that attackers typically use post-exploitation to execute malicious commands.
windows · process_creation
Suspicious File Drop by Exchange
mediumDetects suspicious file type dropped by an Exchange component in IIS
windows · file_event
Suspicious File Write to Webapps Root Directory
mediumDetects suspicious file writes to the root directory of web applications, particularly Apache web servers or Tomcat servers. This may indicate an attempt to deploy malicious files such as web shells or other unauthorized scripts.
windows · file_event
Suspicious OpenSSH Daemon Error
mediumDetects suspicious SSH / SSHD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
linux
Suspicious SQL Query
mediumDetects suspicious SQL query keywrods that are often used during recon, exfiltration or destructive activities. Such as dropping tables and selecting wildcard fields
database
Suspicious User-Agents Related To Recon Tools
mediumDetects known suspicious (default) user-agents related to scanning/recon tools
webserver
Suspicious VSFTPD Error Messages
mediumDetects suspicious VSFTPD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
linux
WordPress Wp2shell REST Batch Endpoint Exploitation
mediumDetects exploitation attempts against the WordPress REST batch endpoint (CVE-2026-63030, CVE-2026-60137) using the wp2shell PoC tool. The tool sends POST requests to the batch endpoint via the ?rest_route=/batch/v1 query parameter, covering all attack phases from initial probe through SQL injection and pre-auth admin creation. A 207 response confirms the endpoint is active on the target.
webserver
Zimbra Collaboration Suite Email Server Unauthenticated RCE
mediumDetects an attempt to leverage the vulnerable servlet "mboximport" for an unauthenticated remote command injection
webserver