Clankerusecase
Web App detection coverage
← Back to main site
Home/ Targets/ Web App

🌐Web App detections

Clankerusecase tracks 50 detection use cases covering the Web App attack surface across 32 MITRE ATT&CK techniques.

Application-layer detections — WAF telemetry, SQLi/XSS/SSRF/RCE, API findings.

Open Detection Library → View on the matrix
50Use cases
32Techniques
20Articles
5Kill-chain phases

Top techniques on Web App (25)

Reconnaissance (1)

[LLM] Gitea process egress to SSRF allow-list bypass internal ranges (CGNAT / 172.32.0.0/11) Bespoke recon · hunting DSΣPDDCS

Delivery (20)

Authentication not detected on admin API endpoint Internal delivery · hunting DD Unauthenticated route returns sensitive PII Internal delivery · alerting DD JWT authentication bypass attempt Internal delivery · alerting DD Local File Inclusion (LFI) exploited Internal delivery · alerting DD Spring4Shell RCE attempts (CVE-2022-22963) Internal delivery · alerting DD Application user activity from Tor Internal delivery · alerting DD Command injection exploited (WAF detection) Internal delivery · alerting DD Credential-stuffing attack on application Internal delivery · alerting DD Distributed credential-stuffing campaign Internal delivery · alerting DD Impossible travel from application business-logic event Internal delivery · alerting DD Log4Shell RCE attempts (CVE-2021-44228) Internal delivery · alerting DD SQL injection exploited (WAF detection) Internal delivery · alerting DD SSRF exploited (WAF detection) Internal delivery · alerting DD [LLM] NodeBB remote federated-user profile lookup (ActivityPub XSS #1 trigger) Bespoke delivery · hunting SΣP [LLM] Credential-phishing form injection via reflected XSS in MantisBT install.php (CVE-2026-52881) Bespoke delivery · alerting SΣP [LLM] Meta open-redirect injection via reflected XSS in MantisBT install.php (CVE-2026-52881) Bespoke delivery · alerting SΣP [LLM] Non-SiYuan process writing synced snippet store data\snippets\conf.json Bespoke delivery · hunting DSΣPDDCS [LLM] Apache Camel DNS SSRF: inbound HTTP request carrying dns.server / dns.name control headers Bespoke delivery · hunting SΣP [LLM] Ghost x-ghost-preview cache-poisoning header in inbound HTTP requests (CVE-2026-53943) Bespoke delivery · hunting SΣPDD [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) Bespoke delivery · alerting DSΣPDD

Exploitation (19)

[LLM] Prebid-server SSRF payload in OpenRTB2 auction request parameters Bespoke exploit · hunting SΣP [LLM] Prebid-server SSRF filter-bypass via encoded internal host in request Bespoke exploit · hunting SΣP [LLM] NodeBB translation-token template-injection XSS in web request URI Bespoke exploit · alerting SΣP [LLM] NodeBB server outbound ActivityPub/webfinger fetch to ephemeral tunnel or new domain Bespoke exploit · hunting DSΣPCS [LLM] NodeBB ActivityPub inbox POST carrying HTML-breakout id (Federation Errors stored XSS) Bespoke exploit · hunting SΣP [LLM] WordPress wp2shell batch REST API pre-auth RCE exploitation (CVE-2026-63030/60137) Bespoke exploit · alerting SΣP [LLM] Broad reflected HTML/XSS payload tokens in MantisBT install.php query string Bespoke exploit · hunting SΣP [LLM] FacturaScripts CVE-2026-45262 SQLi: parenthesis-bypass in REST API filter[] key Bespoke exploit · alerting SΣP [LLM] SiYuan Electron client spawns command interpreter (XSS-to-RCE via child_process) Bespoke exploit · alerting DSΣPDDCS [LLM] SiYuan Electron renderer (nodeIntegration) spawning shell/LOLBin child — XSS-to-RCE Bespoke exploit · alerting DSΣPDDCS [LLM] SSRF via Better Auth SSO provider registration to internal endpoints (CVE-2026-53513) Bespoke exploit · hunting SΣP [LLM] Ghost x-ghost-preview request carrying XSS payload markers (CVE-2026-53943 execution) Bespoke exploit · alerting SΣPDD Article-specific behavioural hunt — Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow Bespoke exploit · hunting DSP Article-specific behavioural hunt — Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195) Bespoke exploit · hunting DSP [LLM] Jinja2 xmlattr XSS exploitation attempt in HTTP request parameters (CVE-2024-22195) Bespoke exploit · alerting SΣP Article-specific behavioural hunt — 84% of all websites are impacted by jQuery XSS vulnerabilities Bespoke exploit · hunting DSP [LLM] Sequelize ORM JSON-path SQLi exploitation via ')) AS DECIMAL)' cast-break (CVE-2019-10748) Bespoke exploit · alerting SΣP Article-specific behavioural hunt — ReDoS vulnerabilities in npm spikes by 143% and XSS continues to grow Bespoke exploit · hunting DSP [LLM] marked Markdown XSS sanitizer bypass — entity-encoded 'javascript&#58' payload in web requests Bespoke exploit · hunting DSΣPCS

Command & Control (1)

[LLM] JFrog Artifactory SSRF egress to non-registry destinations (internet escape) Bespoke c2 · hunting DSΣPCS

Actions on Objectives (9)

Excessive resource consumption of third-party API Internal actions · hunting DD Application data exfiltration successful Internal actions · alerting DD [LLM] Prebid-server outbound requests to internal ranges / internal host fan-out (SSRF) Bespoke actions · alerting DSPDDCSCW [LLM] Prebid-server access to cloud metadata service (169.254.169.254) via SSRF Bespoke actions · hunting DSΣPDDCSCW [LLM] Gitea webhook/migration SSRF reaching cloud metadata endpoints (IMDS / Azure WireServer) Bespoke actions · hunting DSΣPDDCS [LLM] FacturaScripts account takeover: /AdminPlugins access following filter[] SQLi from same source Bespoke actions · alerting SP [LLM] Apache Camel DNS SSRF egress: app server (java) resolving via external / attacker DNS resolver Bespoke actions · hunting DSΣPDDCS [LLM] Web-app runtime egress to AWS IMDS endpoint (169.254.169.254) — SSRF credential theft Bespoke actions · hunting DSΣPDDCS [LLM] SSRF probe via 'instance-data' IMDS alias hostname resolution Bespoke actions · hunting DSΣPDDCS

Recent articles citing Web App-targeted detections