🌐Web App detections
Clankerusecase tracks 25 detection use cases covering the Web App attack surface across 20 MITRE ATT&CK techniques.
Application-layer detections — WAF telemetry, SQLi/XSS/SSRF/RCE, API findings.
25Use cases
20Techniques
7Articles
3Kill-chain phases
Top techniques on Web App (20)
T1190Exploit Public-Facing Application15T1059.007JavaScript4T1204.002Malicious File4T1059Command and Scripting Interpreter3T1078Valid Accounts2T1526Cloud Service Discovery1T1538Cloud Service Dashboard1T1496Resource Hijacking1T1556Modify Authentication Process1T1090.003Multi-hop Proxy1T1110.004Credential Stuffing1T1041Exfiltration Over C2 Channel1T1567Exfiltration Over Web Service1T1110Brute Force1T1550Use Alternate Authentication Material1T1021Remote Services1T1090Proxy1T1566.001Spearphishing Attachment1T1071.001Web Protocols1T1133External Remote Services1