Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084
Detection logic
selection
ParentImage|endswith: \Atlassian\Confluence\jre\bin\java.exe
CommandLine|contains:
- certutil
- cmd /c
- cmd /k
- cscript
- curl
- ipconfig
- powershell
- pwsh
- regsvr32
- rundll32
- whoami
- wscriptCondition
selectionRaw YAML
title: Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
id: 245f92e3-c4da-45f1-9070-bc552e06db11
status: test
description: Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084
references:
- https://nvd.nist.gov/vuln/detail/CVE-2021-26084
- https://confluence.atlassian.com/doc/confluence-security-advisory-2021-08-25-1077906215.html
- https://github.com/h3v0x/CVE-2021-26084_Confluence
author: Bhabesh Raj
date: 2021-09-08
modified: 2023-02-13
tags:
- attack.initial-access
- attack.execution
- attack.t1190
- attack.t1059
- cve.2021-26084
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
# Monitor suspicious child processes spawned by Confluence
ParentImage|endswith: '\Atlassian\Confluence\jre\bin\java.exe'
CommandLine|contains:
- 'certutil'
- 'cmd /c'
- 'cmd /k'
- 'cscript'
- 'curl'
- 'ipconfig'
- 'powershell'
- 'pwsh'
- 'regsvr32'
- 'rundll32'
- 'whoami'
- 'wscript'
condition: selection
falsepositives:
- Unknown
level: highFalse positives
- Unknown
References
Similar rules
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
mediumwindows · Shares T1059, T1190
Windows Suspicious Child Process from Node.js - React2Shell
highwindows · Shares T1059, T1190
Atlassian Confluence CVE-2022-26134
highlinux · Shares T1190, T1059
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux)
highlinux · Shares T1059, T1190