Exploit Public-Facing Application T1190

Tactic: Initial Access

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Events covered

35 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 11FileCreate
SysmonEvent ID 23FileDelete (File Delete archived)
SysmonEvent ID 26FileDeleteDetected (File Delete logged)
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4625An account failed to log on.
Security-AuditingEvent ID 4648A logon was attempted using explicit credentials.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 5136A directory service object was modified.
Security-AuditingEvent ID 5140A network share object was accessed.
Security-AuditingEvent ID 5145A network share object was checked to see whether client can be granted desired access.
Security-AuditingEvent ID 5152The Windows Filtering Platform blocked a packet.
Security-AuditingEvent ID 5154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
Security-AuditingEvent ID 5155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Security-AuditingEvent ID 5157The Windows Filtering Platform has blocked a connection.
Security-AuditingEvent ID 5158The Windows Filtering Platform has permitted a bind to a local port.
Security-AuditingEvent ID 5159The Windows Filtering Platform has blocked a bind to a local port.
Defender-DeviceFileEventsanyFile activity
Defender-DeviceInfoanyDevice information
Defender-DeviceNetworkEventsInboundConnectionAcceptedInbound connection accepted
Defender-DeviceTvmSoftwareVulnerabilitiesanySoftware vulnerabilities on devices
Defender-DeviceTvmSoftwareVulnerabilitiesKBanyVulnerability knowledge base
Defender-ExposureGraphNodesanyExposure graph nodes
ESFexecProcess Execution
ESFcreateFile or Directory Create
ESFrenameFile Rename
MSExchange-Control-PanelEvent ID 4The Exchange Control Panel web application encountered an unhandled ASP.NET exception.
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
MsiInstallerEvent ID 1033Windows Installer installed the product.
Sysmon-for-LinuxEvent ID 1Process Create
Sysmon-for-LinuxEvent ID 11File created
Windows-Server-Update-ServicesEvent ID 7053The WSUS administration console has encountered an unexpected error.

Authoring guide

These 549 rules share fields, values, and exclusions.

Fields filtered most (391 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
cs-method79eq 75, in 4post, get, put, head, options
cs-uri-query58contains 49, match 14, ends_with 4, eq 1, starts_with 1, wildcard 1/ecp/, /help/admin-guide/reports/reportgenerate.jsp, /owa/, /powershell, __viewstate=
process_name50eq 25, in 25, starts_with 5, wildcard 5, regex_match 4, ends_with 3bash, cmd.exe, powershell.exe, busybox, csh
EventType47eq 34, in 7, contains 6exec, intrusionevent, start, creation, exec_event
c-uri46contains 30, in 16, ends_with 4/mgmt/tm/util/bash, /powershell, %40, *${*, *%2f%7b*
parent_process_name43eq 31, in 14, starts_with 8, wildcard 6, regex_match 4, ends_with 2, contains 1, ne 1apache2, *.cgi, *.fcgi, w3wp.exe, node
CommandLine36contains 27, wildcard 9, regex_match 6, is_not_null 3, ends_with 1, in 1, starts_with 1* /dev/shm/*, * /run/*, * /tmp/* , /dev/shm/, /home/
event.type35eq 33, in 2start, creation, change, connection, deletion
ParentImage34ends_with 23, contains 7, wildcard 4, eq 2, starts_with 2/java, /u0*/*, \javaw.exe, \w3wp.exe, -tomcat-
sourcetype34eq 30, in 4cisco:sfw:estreamer, cisco:ios, suricata, cisco:sdwan:syslog, crushftp:sessionlogs
Image32ends_with 26, eq 4, wildcard 4, starts_with 3, contains 2, is_not_null 1, is_null 1\cmd.exe, \bitsadmin.exe, \powershell.exe, \bash.exe, \certutil.exe
Web.status28eq 26, in 2200, 201, 202, 403, 409
ParentCommandLine27contains 23, wildcard 4, in 2, length_compare 1app.py, asgi.py, django, *--port*, */app/*.js*
host.os.type24eq 23, in 1
sc-status24eq 24, contains 1200, 301, 302, 401, 405

Top indicator values (3733 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
cs-methodeq
post
4854
cs-methodeq
get
2949
event.typeeq
start
301078
Web.statuseq
200
2325
sc-statuseq
200
1923
Imageends_with
\cmd.exe
16130
Imageends_with
\powershell.exe
14179
Imageends_with
\pwsh.exe
11165
EventTypeeq
exec
13576
process_namein
bash
13202
process_namein
dash
13170
process_namein
sh
13197
process_namein
zsh
13196
process_namein
ksh
12163
process_namein
busybox
1068
process_namein
csh
10159
process_namein
fish
10163
process_namein
tcsh
10156
HttpRequestMethodeq
get
1112
process_nameeq
cmd.exe
11121
process_nameeq
powershell.exe
10184
parent_process_nameeq
java
914
HttpRequestMethodin
post
812
HttpRequestMethodin
put
812
parent_process_namestarts_with
perl
810
parent_process_namestarts_with
python
825
parent_process_namestarts_with
ruby
810
process.argsin
-c
827
process.argsin
-cl
817
process.argsin
-lc
817

Exclusions (912 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
parent_process_nameeq
apache2
6
parent_process_nameeq
java
6
parent_process_nameeq
asterisk
4
src_ipcidr_match
10.0.0.0/8
6
src_ipcidr_match
127.0.0.0/8
6
src_ipcidr_match
169.254.0.0/16
6
src_ipcidr_match
172.16.0.0/12
6
src_ipcidr_match
192.168.0.0/16
6
src_ipin
10.0.0.0/8
5
src_ipin
127.0.0.0/8
5
src_ipin
169.254.0.0/16
5
src_ipin
172.16.0.0/12
5
src_ipin
192.168.0.0/16
5
src_ipin
::1
5
src_ipin
fe80::/10
5

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 149 rules

Elastic 70 rules

Splunk 121 rules

Kusto 179 rules

YARA-L 1 rule

Panther 29 rules