Exploit Public-Facing Application T1190
Tactic: Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Events covered
23 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 516 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (355 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (3199 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (571 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 146 rules
- ADSelfService Exploitation
- Apache Spark Shell Command Injection - ProcessCreation
- Apache Spark Shell Command Injection - Weblogs
- Apache Threading Error
- Arcadyan Router Exploitations
- Atlassian Bitbucket Command Injection Via Archive API
- Atlassian Confluence CVE-2022-26134
- Cisco ASA Exploitation Activity - Proxy
- Cisco ASA FTD Exploit CVE-2020-3452
- Citrix ADS Exploitation CVE-2020-8193 CVE-2020-8195
- Citrix Netscaler Attack CVE-2019-19781
- Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791)
- Confluence Exploitation CVE-2019-3398
- CVE-2010-5278 Exploitation Attempt
- CVE-2020-0688 Exchange Exploitation via Web Log
- CVE-2020-0688 Exploitation Attempt
- CVE-2020-0688 Exploitation via Eventlog
- CVE-2020-10148 SolarWinds Orion API Auth Bypass
- CVE-2020-5902 F5 BIG-IP Exploitation Attempt
- CVE-2021-21972 VSphere Exploitation
- CVE-2021-21978 Exploitation Attempt
- CVE-2021-33766 Exchange ProxyToken Exploitation
- CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
- CVE-2021-41773 Exploitation Attempt
- CVE-2022-31656 VMware Workspace ONE Access Auth Bypass
- CVE-2022-31659 VMware Workspace ONE Access RCE
- CVE-2023-1389 Potential Exploitation Attempt - Unauthenticated Command Injection In TP-Link Archer AX21
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux)
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
- CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy)
- CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Webserver)
- CVE-2023-46747 Exploitation Activity - Proxy
- CVE-2023-46747 Exploitation Activity - Webserver
- CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
- CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
- CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
- CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
- CVE-2024-50623 Exploitation Attempt - Cleo
- Django Framework Exceptions
- DNS Query to External Service Interaction Domains
- DNS RCE CVE-2020-1350
- Exchange Exploitation CVE-2021-28480
- Exchange Exploitation Used by HAFNIUM
- Exchange ProxyShell Pattern
- Exploitation Activity of CVE-2025-59287 - WSUS Deserialization
- Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
- Exploitation of CVE-2021-26814 in Wazuh
- Exploited CVE-2020-10189 Zoho ManageEngine
- F5 BIG-IP iControl Rest API Command Execution - Proxy
- F5 BIG-IP iControl Rest API Command Execution - Webserver
- Failed Logon From Public IP
- Fortinet CVE-2018-13379 Exploitation
- Fortinet CVE-2021-22123 Exploitation
- Grafana Path Traversal Exploitation CVE-2021-43798
- Hack Tool User Agent
- Ingress/Egress Security Group Modification
- Java Payload Strings
- JNDIExploit Pattern
- Linux Suspicious Child Process from Node.js - React2Shell
- LoadBalancer Security Group Modification
- Log4j RCE CVE-2021-44228 Generic
- Log4j RCE CVE-2021-44228 in Fields
- LPE InstallerFileTakeOver PoC CVE-2021-41379
- OMIGOD HTTP No Authentication RCE - CVE-2021-38647
- OMIGOD SCX RunAsProvider ExecuteScript
- OMIGOD SCX RunAsProvider ExecuteShellCommand
- OpenCanary - FTP Login Attempt
- OpenCanary - HTTP GET Request
- OpenCanary - HTTP POST Login Attempt
- Oracle WebLogic Exploit
- Oracle WebLogic Exploit CVE-2020-14882
- Oracle WebLogic Exploit CVE-2021-2109
- OWASSRF Exploitation Attempt Using Public POC - Proxy
- OWASSRF Exploitation Attempt Using Public POC - Webserver
- Path Traversal Exploitation Attempts
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
- Potential Centos Web Panel Exploitation Attempt - CVE-2022-44877
- Potential CVE-2021-26084 Exploitation Attempt
- Potential CVE-2021-27905 Exploitation Attempt
- Potential CVE-2021-44228 Exploitation Attempt - VMware Horizon
- Potential CVE-2022-21587 Exploitation Attempt
- Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution
- Potential CVE-2022-26809 Exploitation Attempt
- Potential CVE-2022-46169 Exploitation Attempt
- Potential CVE-2023-2283 Exploitation
- Potential CVE-2023-23752 Exploitation Attempt
- Potential CVE-2023-25717 Exploitation Attempt
- Potential CVE-2023-27997 Exploitation Indicators
- Potential Exploitation Attempt Of Undocumented WindowsServer RCE
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
- Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE
- Potential Exploitation of GoAnywhere MFT Vulnerability
- Potential Information Disclosure CVE-2023-43261 Exploitation - Proxy
- Potential Information Disclosure CVE-2023-43261 Exploitation - Web
- Potential JNDI Injection Exploitation In JVM Based Application
- Potential Local File Read Vulnerability In JVM Based Application
- Potential MOVEit Transfer CVE-2023-34362 Exploitation - File Activity
- Potential OGNL Injection Exploitation In JVM Based Application
- Potential OWASSRF Exploitation Attempt - Proxy
- Potential OWASSRF Exploitation Attempt - Webserver
- Potential RCE Exploitation Attempt In NodeJS
- Potential SAP NetViewer Webshell Command Execution
- Potential SAP NetWeaver Webshell Creation
- Potential SAP NetWeaver Webshell Creation - Linux
- Potential Server Side Template Injection In Velocity
- Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create
- Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators
- Potential SpEL Injection In Spring Framework
- Potential XXE Exploitation Attempt In JVM Based Application
- Process Execution Error In JVM Based Application
- ProxyLogon Reset Virtual Directories Based On IIS Log
- Pulse Connect Secure RCE Attack CVE-2021-22893
- Pulse Secure Attack CVE-2019-11510
- Python SQL Exceptions
- RDS Database Security Group Modification
- Rejetto HTTP File Server RCE
- Remote Access Tool - ScreenConnect Server Web Shell Execution
- Ruby on Rails Framework Exceptions
- SharePoint ToolShell CVE-2025-53770 Exploitation - Web IIS
- Sitecore Pre-Auth RCE CVE-2021-42237
- SonicWall SSL/VPN Jarrewrite Exploitation
- Spring Framework Exceptions
- SQL Injection Strings In URI
- Successful IIS Shortname Fuzzing Scan
- Suspicious Child Process of SAP NetWeaver
- Suspicious Child Process of SAP NetWeaver - Linux
- Suspicious Child Process of SolarWinds WebHelpDesk
- Suspicious Child Process Of SQL Server
- Suspicious CrushFTP Child Process
- Suspicious File Drop by Exchange
- Suspicious File Write to SharePoint Layouts Directory
- Suspicious File Write to Webapps Root Directory
- Suspicious MSExchangeMailboxReplication ASPX Write
- Suspicious Named Error
- Suspicious OpenSSH Daemon Error
- Suspicious Process By Web Server Process
- Suspicious Processes Spawned by WinRM
- Suspicious SQL Error Messages
- Suspicious SQL Query
- Suspicious User-Agents Related To Recon Tools
- Suspicious VSFTPD Error Messages
- Terminal Service Process Spawn
- TerraMaster TOS CVE-2020-28188
- VMware vCenter Server File Upload CVE-2021-22005
- Windows Suspicious Child Process from Node.js - React2Shell
- Zimbra Collaboration Suite Email Server Unauthenticated RCE
Elastic 50 rules
- Accepted Default Telnet Port Connection
- Anomalous React Server Components Flight Data Patterns
- Deprecated - Unusual Command Execution from Web Server Parent
- Deprecated - Unusual Process Spawned from Web Server Parent
- FortiGate FortiCloud SSO Login from Unusual Source
- Inbound Connection to an Unsecure Elasticsearch Node
- Initial Access via File Upload Followed by GET Request
- Microsoft Exchange Server UM Spawning Suspicious Processes
- Microsoft Exchange Server UM Writing Suspicious Files
- Microsoft Exchange Worker Spawning Suspicious Processes
- Ollama API Accessed from External Network
- Potential Buffer Overflow Attack Detected
- Potential Code Execution via Postgresql
- Potential cPanel WHM CRLF Authentication Bypass (CVE-2026-41940)
- Potential JAVA/JNDI Exploitation Attempt
- Potential Linux Hack Tool Launched
- Potential SAP NetWeaver Exploitation
- Potential Telnet Authentication Bypass (CVE-2026-24061)
- Potential Toolshell Initial Exploit (CVE-2025-53770 & CVE-2025-53771)
- Potential VIEWSTATE RCE Attempt on SharePoint/IIS
- Potential Webshell Deployed via Apache Struts CVE-2023-50164 Exploitation
- RDP (Remote Desktop Protocol) from the Internet
- React2Shell (CVE-2025-55182) Exploitation Attempt
- React2Shell Network Security Alert
- RPC (Remote Procedure Call) from the Internet
- RPC (Remote Procedure Call) to the Internet
- ScreenConnect Server Spawning Suspicious Processes
- SMB (Windows File Sharing) Activity to the Internet
- Suspicious Child Execution via Web Server
- Suspicious Command Execution via Web Server
- Suspicious JetBrains TeamCity Child Process
- Suspicious React Server Child Process
- Suspicious SolarWinds Web Help Desk Java Module Load or Child Process
- Telnet Authentication Bypass via User Environment Variable
- Unusual Child Execution via Web Server
- Unusual Child Process of dns.exe
- Unusual Command Execution via Web Server
- Unusual Exim4 Child Process
- Unusual File Creation by Web Server
- Unusual File Operation by dns.exe
- Unusual Process For MSSQL Service Accounts
- VNC (Virtual Network Computing) from the Internet
- Web Server Exploitation Detected via Defend for Containers
- Web Server Local File Inclusion Activity
- Web Server Potential Command Injection Request
- Web Server Potential Remote File Inclusion Activity
- Web Server Potential SQL Injection Request
- Web Shell Detection: Script Process Child of Common Web Processes
- Windows Server Update Service Spawning Suspicious Processes
- Zoom Meeting with no Passcode
Splunk 118 rules
- Access to Vulnerable Ivanti Connect Secure Bookmark Endpoint
- Adobe ColdFusion Access Control Bypass
- Adobe ColdFusion Unauthenticated Arbitrary File Read
- Cisco IOS XE Implant Access
- Cisco IOS XE Request Platform Package Describe Shell Pattern
- Cisco IOS XE WebUI Login From IOSd Local Port
- Cisco IOS XE WebUI Programmatic Configuration
- Cisco NVM - Webserver Download From File Sharing Website
- Cisco SD-WAN - Arbitrary File Overwrite Exploitation Activity
- Cisco SD-WAN - Low Frequency Rogue Peer
- Cisco SD-WAN - Peering Activity
- Cisco Secure Firewall - High Priority Intrusion Classification
- Cisco Secure Firewall - Lumma Stealer Activity
- Cisco Secure Firewall - Oracle E-Business Suite Correlation
- Cisco Secure Firewall - Oracle E-Business Suite Exploitation
- Cisco Secure Firewall - React Server Components RCE Attempt
- Cisco Secure Firewall - Static Tundra Smart Install Abuse
- Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity
- Cisco Smart Install Oversized Packet Detection
- Cisco Smart Install Port Discovery and Status
- Citrix ADC and Gateway CitrixBleed 2 Memory Disclosure
- Citrix ADC and Gateway Unauthorized Data Disclosure
- Citrix ADC Exploitation CVE-2023-3519
- Citrix ShareFile Exploitation CVE-2023-24489
- Confluence CVE-2023-22515 Trigger Vulnerability
- Confluence Data Center and Server Privilege Escalation
- Confluence Pre-Auth RCE via OGNL Injection CVE-2023-22527
- Confluence Unauthenticated Remote Code Execution CVE-2022-26134
- ConnectWise ScreenConnect Authentication Bypass
- ConnectWise ScreenConnect Path Traversal
- ConnectWise ScreenConnect Path Traversal Windows SACL
- CrushFTP Authentication Bypass Exploitation
- CrushFTP Server Side Template Injection
- Detect Exchange Web Shell
- Detect F5 TMUI RCE CVE-2020-5902
- Detect Outbound LDAP Traffic
- Detect Zerologon via Zeek
- Exchange PowerShell Abuse via SSRF
- Exploit Public Facing Application via Apache Commons Text
- Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952
- F5 BIG-IP iControl REST Vulnerability CVE-2022-1388
- Fortinet Appliance Auth bypass
- HTTP Duplicated Header
- HTTP Rapid POST with Mixed Status Codes
- HTTP Request to Reserved Name on IIS Server
- Hunting for Log4Shell
- Ivanti Connect Secure Command Injection Attempts
- Ivanti Connect Secure SSRF in SAML Component
- Ivanti Connect Secure System Information Access via Auth Bypass
- Ivanti EPM SQL Injection Remote Code Execution
- Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078
- Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082
- Ivanti VTM New Account Creation
- Java Class File download by Java User Agent
- Java Writing JSP File
- Jenkins Arbitrary File Read CVE-2024-23897
- JetBrains TeamCity Authentication Bypass CVE-2024-27198
- JetBrains TeamCity Authentication Bypass Suricata CVE-2024-27198
- JetBrains TeamCity Limited Auth Bypass Suricata CVE-2024-27199
- JetBrains TeamCity RCE Attempt
- Juniper Networks Remote Code Execution Exploit Detection
- Linux Suspicious React or Next.js Child Process
- Living Off The Land Detection
- Log4Shell CVE-2021-44228 Exploitation
- Log4Shell JNDI Payload Injection Attempt
- Log4Shell JNDI Payload Injection with Outbound Connection
- Microsoft SQL Server Suspicious Child Process - Windows (Sysmon)
- Microsoft SQL Server Suspicious Child Process - Windows (Windows Event Log)
- MOVEit Certificate Store Access Failure
- MOVEit Empty Key Fingerprint Authentication Attempt
- MS Exchange Mailbox Replication service writing Active Server Pages
- Nginx ConnectWise ScreenConnect Authentication Bypass
- Ollama Possible RCE via Model Loading
- Ollama Suspicious Prompt Injection Jailbreak
- Outbound Network Connection from Java Using Default Ports
- PaperCut NG Remote Web Access Attempt
- PaperCut NG Suspicious Behavior Debug Log
- Potential Exposed SMB_RDP Port - Windows (Windows Event Log)
- Potential SMB Activity from External IP - Windows (Windows Event Log)
- ProxyShell ProxyNotShell Behavior Detected
- SAP NetWeaver Visual Composer Exploitation Attempt
- Spring4Shell Payload URL Request
- SQL Injection with Long URLs
- Suspicious Confluence Child Process - Windows (Sysmon)
- Suspicious Confluence Child Process - Windows (Windows Event Log)
- Suspicious Java Classes
- Tomcat Session Deserialization Attempt
- Tomcat Session File Upload Attempt
- VMWare Aria Operations Exploit Attempt
- VMware Server Side Template Injection Hunt
- VMware Workspace ONE Freemarker Server-side Template Injection
- Web JSP Request via URL
- Web or Application Server Spawning a Shell
- Web Remote ShellServlet Access
- Web Spring Cloud Function FunctionRouter
- Web Spring4Shell HTTP Request Class Module
- WebLogic CVE-2017-10271 (PowerShell)
- WebLogic CVE-2017-10271 (Sysmon)
- WebLogic CVE-2017-10271 (Windows Event Log)
- Windows Exchange Autodiscover SSRF Abuse
- Windows Identify PowerShell Web Access IIS Pool
- Windows IIS Server PSWA Console Access
- Windows Metasploit Confluence Plugin Execution
- Windows MOVEit Transfer Writing ASPX
- Windows PaperCut NG Spawn Shell
- Windows SharePoint Spinstall0 GET Request
- Windows SharePoint Spinstall0 Webshell File Creation
- Windows SharePoint ToolPane Endpoint Exploitation Attempt
- Windows Shell or Script Execution From IIS Directory
- Windows Shell Process from CrushFTP
- Windows Suspicious React or Next.js Child Process
- Windows TeamCity Payload Execution from Temp Directory
- Windows TeamCity Plugin Installed
- Windows Unusual File Creation in Confluence Directory
- Windows WSUS Spawning Shell
- WinRM Spawning a Process
- WordPress Bricks Builder plugin RCE
- WS FTP Remote Code Execution
Kusto 172 rules
- A potentially malicious web request was executed against a web server
- Abnormal Deny Rate for Source IP
- AFD WAF - Code Injection
- AFD WAF - Path Traversal Attack
- Anomalous User Agent connection attempt
- Apache - Apache 2.4.49 flaw CVE-2021-41773
- Apache - Command in URI
- Apache - Known malicious user agent
- Apache - Multiple client errors from single IP
- Apache - Multiple server errors from single IP
- Apache - Private IP in URL
- Apache - Put suspicious file
- Apache - Request from private IP
- Apache - Requests to rare files
- ApexOne - Attack Discovery Detection
- ApexOne - Commands in Url
- ApexOne - Multiple deny or terminate actions on single IP
- ApexOne - Spyware with failed response
- API - JWT validation
- API - Rate limiting
- API - Suspicious Login
- App Gateway WAF - Scanner Detection
- App Gateway WAF - SQLi Detection
- App GW WAF - Code Injection
- App GW WAF - Path Traversal Attack
- Application Gateway WAF - SQLi Detection
- AV detections related to SpringShell Vulnerability
- Azure WAF matching for Log4j vuln(CVE-2021-44228)
- BitSight - new alert found
- BitSight - new breach found
- Cisco SDWAN - Intrusion Events
- Cisco SDWAN - IPS Event Threshold
- Cisco SE - Malware outbreak
- Cisco SE - Multiple malware on host
- Cisco SE - Unexpected binary file
- Cisco SE High Events Last Hour
- Claroty - Login to uncommon location
- Claroty - Multiple failed logins by user
- Claroty - Multiple failed logins to same destinations
- Claroty - New Asset
- Cloudflare - Bad client IP
- Cloudflare - Bad client IP
- Cloudflare - Client request from country in blocklist
- Cloudflare - Client request from country in blocklist
- Cloudflare - Empty user agent
- Cloudflare - Empty user agent
- Cloudflare - Multiple error requests from single source
- Cloudflare - Multiple error requests from single source
- Cloudflare - Multiple user agents for single source
- Cloudflare - Multiple user agents for single source
- Cloudflare - Unexpected client request
- Cloudflare - Unexpected client request
- Cloudflare - Unexpected URI
- Cloudflare - Unexpected URI
- Cloudflare - WAF Allowed threat
- Cloudflare - WAF Allowed threat
- Cloudflare - XSS probing pattern in request
- Cloudflare - XSS probing pattern in request
- Credential errors stateful anomaly on database
- Dataverse - Login by a sensitive privileged user
- Dataverse - Login from IP in the block list
- Dataverse - Login from IP not in the allow list
- Dataverse - New sign-in from an unauthorized domain
- Dataverse - New user agent type that was not used with Office 365
- Dataverse - Suspicious use of TDS endpoint
- Detect instances of multiple client errors occurring within a brief period of time (ASIM Web Session)
- Detect instances of multiple server errors occurring within a brief period of time (ASIM Web Session)
- Detect known risky user agents (ASIM Web Session)
- Detect Local File Inclusion(LFI) in web requests (ASIM Web Session)
- Detect port misuse by anomaly based detection (ASIM Network Session schema)
- Detect port misuse by static threshold (ASIM Network Session schema)
- Detect presence of uncommon user agents in web requests (ASIM Web Session)
- Detect threat information in web requests (ASIM Web Session)
- Detect URLs containing known malicious keywords or commands (ASIM Web Session)
- Dynatrace Application Security - Attack detection
- Exchange OAB Virtual Directory Attribute Containing Potential Webshell
- Exchange Server Suspicious File Downloads.
- Exchange SSRF Autodiscover ProxyShell - Detection
- Failed sign-ins into LastPass due to MFA
- Firewall errors stateful anomaly on database
- Fortiweb - WAF Allowed threat
- Front Door Premium WAF - SQLi Detection
- GCP Security Command Center - Detect Open/Unrestricted API Keys
- GitHub Security Vulnerability in Repository
- GWorkspace - Alert events
- High count of connections by client IP on many ports
- High Number of Urgent Vulnerabilities Detected
- High severity malicious activity detected
- Hunt for public facing devices and exposed ports over time
- Hunt for public facing devices via DeviceNetworkEvents
- Hunt for public facing devices via public tag
- Hunt for public remotly exploitable devices (with high EPSS)
- Identify instances where a single source is observed using multiple user agents (ASIM Web Session)
- Identify SysAid Server web shell creation
- Imperva - Abnormal protocol usage
- Imperva - Critical severity event not blocked
- Imperva - Forbidden HTTP request method in request
- Imperva - Malicious Client
- Imperva - Malicious user agent
- Imperva - Multiple user agents from same source
- Imperva - Possible command injection
- Imperva - Request from unexpected countries
- Imperva - Request from unexpected IP address to admin panel
- Imperva - Request to unexpected destination port
- Microsoft Defender for Endpoint (MDE) signatures for Azure Synapse pipelines and Azure Data Factory
- New High Severity Vulnerability Detected Across Multiple Hosts
- NGINX - Command in URI
- NGINX - Known malicious user agent
- NGINX - Multiple client errors from single IP address
- NGINX - Multiple server errors from single IP address
- NGINX - Multiple user agents for single source
- NGINX - Private IP address in URL
- NGINX - Put file and get file from same IP address
- NGINX - Sql injection patterns
- OCI - Inbound SSH connection
- OCI - Unexpected user agent
- OLE object manipulation attempts stateful anomaly on database
- OMI Vulnerability Exploitation
- Oracle - Command in URI
- Oracle - Malicious user agent
- Oracle - Multiple client errors from single IP
- Oracle - Multiple server errors from single IP
- Oracle - Multiple user agents for single source
- Oracle - Oracle WebLogic Exploit CVE-2021-2109
- Oracle - Private IP in URL
- Oracle - Put file and get file from same IP address
- Oracle - Put suspicious file
- OracleDBAudit - Connection to database from external IP
- OracleDBAudit - SQL injection patterns
- PaloAlto - Dropping or denying session with traffic
- PaloAlto - File type changed
- PaloAlto - Forbidden countries
- PaloAlto - Inbound connection to high risk ports
- PaloAlto - MAC address conflict
- PaloAlto - Possible attack without response
- PaloAlto - Possible flooding
- PaloAlto - Put and post method request in high risk file type
- PaloAlto - User privileges was changed
- Pathlock TDnR - J2EE Security Events
- Pathlock TDnR - SAP HTTP Webserver Events
- Pathlock TDnR - SAP Web Dispatcher HTTP Events
- Ping Federate - OAuth old version
- Ping Federate - SAML old version
- PulseConnectSecure - CVE-2021-22893 Possible Pulse Connect Secure RCE Vulnerability Attack
- Sentinel One - Alert from custom rule
- Sentinel One - Multiple alerts on host
- Sentinel One - Same custom rule triggered on different hosts
- Silk Typhoon New UM Service Child Process
- Silk Typhoon Suspicious Exchange Request
- Silk Typhoon Suspicious File Downloads.
- Silk Typhoon Suspicious UM Service Error
- Silverfort - Log4Shell Incident
- SonicWall - Allowed SSH, Telnet, and RDP Connections
- Syntax errors stateful anomaly on database
- Tomcat - Commands in URI
- Tomcat - Known malicious user agent
- Tomcat - Multiple client errors from single IP address
- Tomcat - Multiple empty requests from same IP
- Tomcat - Multiple server errors from single IP address
- Tomcat - Put file and get file from same IP address
- Tomcat - Request from localhost IP address
- Tomcat - Server errors after multiple requests from same IP
- Tomcat - Sql injection patterns
- User agent search for log4j exploitation attempt
- VMware ESXi - Dormant VM started
- Vulnerable Machines related to log4j CVE-2021-44228
- Vulnerable Machines related to OMIGOD CVE-2021-38647
- Web Application attack detected
- Zscaler - Forbidden countries
- Zscaler - Unexpected update operation
- Zscaler - ZPA connections from new country
- Zscaler - ZPA connections outside operational hours
YARA-L 1 rule
Panther 29 rules
- AppOmni Alert Passthrough
- AWS Application Load Balancer Web ACL
- AWS ELB SSL Policies
- AWS Enforces SSL Policies
- AWS Lambda Public Access
- AWS Network ACL Restricts Inbound Traffic
- AWS Security Group - Only DMZ Publicly Accessible
- AWS Security Group Administrative Ingress
- AWS Security Group Restricts Access To CDE
- AWS Security Group Restricts Inbound Traffic
- AWS Security Group Tightly Restricts Inbound Traffic
- AWS WAF Has XSS Predicate
- AWS WAF Managed Admin Protection Passthrough Rule
- AWS WAF Managed Core Rule Set Passthrough Rule
- AWS WAF Managed IP Reputation Passthrough Rule
- AWS WAF Managed Known Bad Inputs Passthrough Rule
- AWS WAF Managed SQL Database Passthrough Rule
- AWS WAF ReactJS RCE Attempt via Body
- CVE-2023-7028 - GitLab Audit Password Reset Multiple Emails
- CVE-2023-7028 - GitLab Production Password Reset Multiple Emails
- EKS Anonymous API Access Detected
- EKS Audit Log Reporting system Namespace is Used From A Public IP
- GCP K8S Service Type NodePort Deployed
- Kubernetes Anonymous API Access Detected
- Kubernetes NodePort Service Deployed
- Kubernetes System Principal Accessed from Non-Cloud Public IP
- S3 Public Access Block Deleted
- Upwind API Detection Passthrough
- Upwind Vulnerability Detection Passthrough