Platform / product
paloalto Sigma detection rules
2 community-maintained Sigma detection rules in the library target the paloalto platform, covering log sources such as appliance, file_event. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.
Log sources
Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection
highDetects potential exploitation attempts of CVE-2024-3400 - an OS command injection in Palo Alto GlobalProtect. This detection looks for suspicious strings that indicate a potential directory traversal attempt or command injection.
paloalto · globalprotect
Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection - File Creation
mediumDetects suspicious file creations in the Palo Alto Networks PAN-OS' parent telemetry folder, which are processed by the vulnerable 'dt_curl' script if device telemetry is enabled. As said script overrides the shell-subprocess restriction, arbitrary command execution may occur by carefully crafting filenames that are escaped through this function.
paloalto · globalprotect