MITRE ATT&CK technique
Template Injection detection rulesT1221
Template Injection (T1221) is a MITRE ATT&CK technique in the Stealth tactic. This page lists the 2 community-maintained Sigma detection rules in the library mapped to T1221 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
T1221 on attack.mitre.org2 rules
Server Side Template Injection Strings
highDetects SSTI attempts sent via GET requests in access logs
webserver
Suspicious Set Value of MSDT in Registry (CVE-2022-30190)
mediumDetects set value ms-msdt MSProtocol URI scheme in Registry that could be an attempt to exploit CVE-2022-30190.
windows · registry_set