Clankerusecase
Web App detection coverage
← Back to main site
Home/ Targets/ Web App

🌐Web App detections

Clankerusecase tracks 52 detection use cases covering the Web App attack surface across 34 MITRE ATT&CK techniques.

Application-layer detections — WAF telemetry, SQLi/XSS/SSRF/RCE, API findings.

Open Detection Library → View on the matrix
52Use cases
34Techniques
20Articles
5Kill-chain phases

Top techniques on Web App (25)

Reconnaissance (1)

[LLM] Gitea process egress to SSRF allow-list bypass internal ranges (CGNAT / 172.32.0.0/11) Bespoke recon · hunting DSΣPDDCS

Delivery (20)

Authentication not detected on admin API endpoint Internal delivery · hunting DD Unauthenticated route returns sensitive PII Internal delivery · alerting DD JWT authentication bypass attempt Internal delivery · alerting DD Local File Inclusion (LFI) exploited Internal delivery · alerting DD Spring4Shell RCE attempts (CVE-2022-22963) Internal delivery · alerting DD Application user activity from Tor Internal delivery · alerting DD Command injection exploited (WAF detection) Internal delivery · alerting DD Credential-stuffing attack on application Internal delivery · alerting DD Distributed credential-stuffing campaign Internal delivery · alerting DD Impossible travel from application business-logic event Internal delivery · alerting DD Log4Shell RCE attempts (CVE-2021-44228) Internal delivery · alerting DD SQL injection exploited (WAF detection) Internal delivery · alerting DD SSRF exploited (WAF detection) Internal delivery · alerting DD [LLM] Sequelize Oracle SQLi: TO_DATE/TO_TIMESTAMP quote-bypass payload in HTTP request Bespoke delivery · alerting SΣP [LLM] Malicious vault-addr annotation on ConfigMap/Secret admission (CVE-2026-54725) Bespoke delivery · alerting SΣPDD [LLM] NodeBB remote federated-user profile lookup (ActivityPub XSS #1 trigger) Bespoke delivery · hunting SΣP [LLM] Credential-phishing form injection via reflected XSS in MantisBT install.php (CVE-2026-52881) Bespoke delivery · alerting SΣP [LLM] Meta open-redirect injection via reflected XSS in MantisBT install.php (CVE-2026-52881) Bespoke delivery · alerting SΣP [LLM] Non-SiYuan process writing synced snippet store data\snippets\conf.json Bespoke delivery · hunting DSΣPDDCS [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) Bespoke delivery · alerting DSΣPDD

Exploitation (20)

[LLM] MLflow unauthenticated webhook create + /test SSRF exploitation (CVE-2026-64849) Bespoke exploit · alerting SΣP [LLM] MLflow/Python server egress to cloud metadata IP 169.254.169.254 (SSRF landing) Bespoke exploit · hunting DSΣPDDCS [LLM] CVE-2026-52887 SQLi payload in NocoBase myInAppChannels filter[latestMsgReceiveTimestamp][$lt] Bespoke exploit · alerting SΣP [LLM] Flyto2 flyto-verification unauthenticated POST /run on :8344 (CVE-2026-67426 SSRF entry) Bespoke exploit · hunting DSΣPCS [LLM] Prebid-server SSRF payload in OpenRTB2 auction request parameters Bespoke exploit · hunting SΣP [LLM] Prebid-server SSRF filter-bypass via encoded internal host in request Bespoke exploit · hunting SΣP [LLM] NodeBB server outbound ActivityPub/webfinger fetch to ephemeral tunnel or new domain Bespoke exploit · hunting DSΣPCS [LLM] NodeBB ActivityPub inbox POST carrying HTML-breakout id (Federation Errors stored XSS) Bespoke exploit · hunting SΣP [LLM] WordPress wp2shell batch REST API pre-auth RCE exploitation (CVE-2026-63030/60137) Bespoke exploit · alerting SΣP [LLM] Broad reflected HTML/XSS payload tokens in MantisBT install.php query string Bespoke exploit · hunting SΣP [LLM] FacturaScripts CVE-2026-45262 SQLi: parenthesis-bypass in REST API filter[] key Bespoke exploit · alerting SΣP [LLM] SiYuan Electron client spawns command interpreter (XSS-to-RCE via child_process) Bespoke exploit · alerting DSΣPDDCS [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow Bespoke exploit · hunting DSP Article-specific behavioural hunt — Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195) Bespoke exploit · hunting DSP [LLM] Jinja2 xmlattr XSS exploitation attempt in HTTP request parameters (CVE-2024-22195) Bespoke exploit · alerting SΣP Article-specific behavioural hunt — 84% of all websites are impacted by jQuery XSS vulnerabilities Bespoke exploit · hunting DSP [LLM] Sequelize ORM JSON-path SQLi exploitation via ')) AS DECIMAL)' cast-break (CVE-2019-10748) Bespoke exploit · alerting SΣP Article-specific behavioural hunt — ReDoS vulnerabilities in npm spikes by 143% and XSS continues to grow Bespoke exploit · hunting DSP [LLM] marked Markdown XSS sanitizer bypass — entity-encoded 'javascript&#58' payload in web requests Bespoke exploit · hunting DSΣPCS

Command & Control (1)

[LLM] vault-secrets-webhook pod outbound SSRF egress to cloud IMDS (CVE-2026-54725) Bespoke c2 · alerting DSΣPCS

Actions on Objectives (10)

Excessive resource consumption of third-party API Internal actions · hunting DD Application data exfiltration successful Internal actions · alerting DD [WEEKLY] SSRF-Driven Secret Egress: Public-Facing App Reaches Cloud Metadata/Attacker Host Internal actions · alerting DSΣPDDCSCW [LLM] flyto-verification SSRF to cloud metadata IP (169.254.169.254) — runner-secret/IMDS theft Bespoke actions · hunting DSΣPDDCS [LLM] Prebid-server outbound requests to internal ranges / internal host fan-out (SSRF) Bespoke actions · alerting DSPDDCSCW [LLM] Prebid-server access to cloud metadata service (169.254.169.254) via SSRF Bespoke actions · hunting DSΣPDDCSCW [LLM] Gitea webhook/migration SSRF reaching cloud metadata endpoints (IMDS / Azure WireServer) Bespoke actions · hunting DSΣPDDCS [LLM] FacturaScripts account takeover: /AdminPlugins access following filter[] SQLi from same source Bespoke actions · alerting SP [LLM] Web-app runtime egress to AWS IMDS endpoint (169.254.169.254) — SSRF credential theft Bespoke actions · hunting DSΣPDDCS [LLM] SSRF probe via 'instance-data' IMDS alias hostname resolution Bespoke actions · hunting DSΣPDDCS

Recent articles citing Web App-targeted detections