Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Initial Access/ T1190

T1190Exploit Public-Facing Application

T1190 — Exploit Public-Facing Application is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 487 detection use cases covering it and 2549 threat-intel articles citing it.

Initial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
487Use cases
2549Articles
0Sub-techniques
1Tactic

Use cases covering this technique (487)

Authentication not detected on admin API endpoint Internal delivery · hunting DD Excessive resource consumption of third-party API Internal actions · hunting DD JWT authentication bypass attempt Internal delivery · alerting DD Local File Inclusion (LFI) exploited Internal delivery · alerting DD Spring4Shell RCE attempts (CVE-2022-22963) Internal delivery · alerting DD AWS S3 bucket ACL / policy made public Internal actions · alerting DDCW Command injection exploited (WAF detection) Internal delivery · alerting DD Distributed credential-stuffing campaign Internal delivery · alerting DD Log4Shell RCE attempts (CVE-2021-44228) Internal delivery · alerting DD SQL injection exploited (WAF detection) Internal delivery · alerting DD SSRF exploited (WAF detection) Internal delivery · alerting DD Asset exposure — vulnerability matches article CVE(s) Internal recon · alerting DSP [WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Internal exploit · alerting DSΣPDDCS [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD [WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) Internal install · alerting DSΣPDDCS [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD Cisco IOS XE Request Platform Package Describe Shell Pattern ESCU actions · alerting P Cisco IOS XE WebUI Login From IOSd Local Port ESCU actions · alerting P Cisco IOS XE WebUI Programmatic Configuration ESCU actions · hunting P CrushFTP Server Side Template Injection ESCU actions · alerting P Ivanti VTM New Account Creation ESCU actions · alerting P Ollama Possible RCE via Model Loading ESCU actions · hunting P Ollama Suspicious Prompt Injection Jailbreak ESCU actions · hunting P PTC Windchill Gateway Command Execution ESCU actions · hunting P PTC Windchill GW READY OK Probe ESCU actions · hunting P Suspicious Java Classes ESCU actions · hunting P Cisco NVM - Webserver Download From File Sharing Website ESCU actions · alerting P ConnectWise ScreenConnect Path Traversal ESCU actions · alerting P ConnectWise ScreenConnect Path Traversal Windows SACL ESCU actions · alerting P Detect Exchange Web Shell ESCU actions · alerting P Exchange PowerShell Abuse via SSRF ESCU actions · alerting P Java Writing JSP File ESCU actions · alerting P Linux Suspicious React or Next.js Child Process ESCU actions · alerting P Living Off The Land Detection ESCU actions · alerting P Log4Shell CVE-2021-44228 Exploitation ESCU actions · alerting P MOVEit Certificate Store Access Failure ESCU actions · hunting P MOVEit Empty Key Fingerprint Authentication Attempt ESCU actions · hunting P MS Exchange Mailbox Replication service writing Active Server Pages ESCU actions · alerting P Outbound Network Connection from Java Using Default Ports ESCU actions · alerting P PaperCut NG Suspicious Behavior Debug Log ESCU actions · hunting P Web or Application Server Spawning a Shell ESCU actions · alerting P Windows Identify PowerShell Web Access IIS Pool ESCU actions · hunting P Windows Metasploit Confluence Plugin Execution ESCU actions · alerting P Windows MOVEit Transfer Writing ASPX ESCU actions · alerting P Windows PaperCut NG Spawn Shell ESCU actions · alerting P Windows SharePoint Spinstall0 Webshell File Creation ESCU actions · alerting P Windows Shell or Script Execution From IIS Directory ESCU actions · hunting P Windows Shell Process from CrushFTP ESCU actions · alerting P Windows Suspicious React or Next.js Child Process ESCU actions · alerting P Windows TeamCity Payload Execution from Temp Directory ESCU actions · alerting P Windows TeamCity Plugin Installed ESCU actions · hunting P Windows Unusual File Creation in Confluence Directory ESCU actions · hunting P Windows WSUS Spawning Shell ESCU actions · alerting P WinRM Spawning a Process ESCU actions · alerting P Cisco SD-WAN - Arbitrary File Overwrite Exploitation Activity ESCU actions · alerting P Cisco SD-WAN - Low Frequency Rogue Peer ESCU actions · hunting P Cisco SD-WAN - Peering Activity ESCU actions · hunting P Cisco Secure Firewall - High Priority Intrusion Classification ESCU actions · alerting P Cisco Secure Firewall - Lumma Stealer Activity ESCU actions · alerting P Cisco Secure Firewall - Oracle E-Business Suite Correlation ESCU actions · alerting P Cisco Secure Firewall - Oracle E-Business Suite Exploitation ESCU actions · alerting P Cisco Secure Firewall - React Server Components RCE Attempt ESCU actions · alerting P Cisco Secure Firewall - Static Tundra Smart Install Abuse ESCU actions · alerting P Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity ESCU actions · alerting P Cisco Smart Install Oversized Packet Detection ESCU actions · alerting P Cisco Smart Install Port Discovery and Status ESCU actions · alerting P Detect Outbound LDAP Traffic ESCU actions · hunting P Detect Zerologon via Zeek ESCU actions · alerting P F5 BIG-IP iControl REST Vulnerability CVE-2022-1388 ESCU actions · alerting P Access to Vulnerable Ivanti Connect Secure Bookmark Endpoint ESCU actions · alerting P Adobe ColdFusion Access Control Bypass ESCU actions · hunting P Adobe ColdFusion Unauthenticated Arbitrary File Read ESCU actions · hunting P Cisco IOS XE Implant Access ESCU actions · alerting P Citrix ADC and Gateway CitrixBleed 2 Memory Disclosure ESCU actions · hunting P Citrix ADC and Gateway Unauthorized Data Disclosure ESCU actions · alerting P Citrix ADC Exploitation CVE-2023-3519 ESCU actions · hunting P Citrix ShareFile Exploitation CVE-2023-24489 ESCU actions · hunting P Confluence CVE-2023-22515 Trigger Vulnerability ESCU actions · alerting P Confluence Data Center and Server Privilege Escalation ESCU actions · alerting P Confluence Pre-Auth RCE via OGNL Injection CVE-2023-22527 ESCU actions · alerting P Confluence Unauthenticated Remote Code Execution CVE-2022-26134 ESCU actions · alerting P ConnectWise ScreenConnect Authentication Bypass ESCU actions · alerting P CrushFTP Authentication Bypass Exploitation ESCU actions · alerting P Detect F5 TMUI RCE CVE-2020-5902 ESCU actions · alerting P Exploit Public Facing Application via Apache Commons Text ESCU actions · hunting P Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 ESCU actions · alerting P Fortinet Appliance Auth bypass ESCU actions · alerting P HTTP Duplicated Header ESCU actions · hunting P HTTP Rapid POST with Mixed Status Codes ESCU actions · hunting P HTTP Request to Reserved Name on IIS Server ESCU actions · alerting P Hunting for Log4Shell ESCU actions · hunting P Ivanti Connect Secure Command Injection Attempts ESCU actions · alerting P Ivanti Connect Secure SSRF in SAML Component ESCU actions · alerting P Ivanti Connect Secure System Information Access via Auth Bypass ESCU actions · hunting P Ivanti EPM SQL Injection Remote Code Execution ESCU actions · alerting P Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078 ESCU actions · alerting P Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082 ESCU actions · alerting P Java Class File download by Java User Agent ESCU actions · alerting P Jenkins Arbitrary File Read CVE-2024-23897 ESCU actions · alerting P JetBrains TeamCity Authentication Bypass CVE-2024-27198 ESCU actions · alerting P JetBrains TeamCity Authentication Bypass Suricata CVE-2024-27198 ESCU actions · alerting P JetBrains TeamCity Limited Auth Bypass Suricata CVE-2024-27199 ESCU actions · alerting P JetBrains TeamCity RCE Attempt ESCU actions · alerting P Juniper Networks Remote Code Execution Exploit Detection ESCU actions · alerting P Log4Shell JNDI Payload Injection Attempt ESCU actions · hunting P Log4Shell JNDI Payload Injection with Outbound Connection ESCU actions · hunting P Nginx ConnectWise ScreenConnect Authentication Bypass ESCU actions · alerting P PaperCut NG Remote Web Access Attempt ESCU actions · alerting P ProxyShell ProxyNotShell Behavior Detected ESCU actions · alerting P SAP NetWeaver Visual Composer Exploitation Attempt ESCU actions · hunting P Spring4Shell Payload URL Request ESCU actions · alerting P SQL Injection with Long URLs ESCU actions · alerting P Tomcat Session Deserialization Attempt ESCU actions · hunting P Tomcat Session File Upload Attempt ESCU actions · hunting P VMWare Aria Operations Exploit Attempt ESCU actions · alerting P VMware Server Side Template Injection Hunt ESCU actions · hunting P VMware Workspace ONE Freemarker Server-side Template Injection ESCU actions · hunting P Web JSP Request via URL ESCU actions · alerting P Web Remote ShellServlet Access ESCU actions · alerting P Web Spring4Shell HTTP Request Class Module ESCU actions · alerting P Web Spring Cloud Function FunctionRouter ESCU actions · alerting P Windows Exchange Autodiscover SSRF Abuse ESCU actions · alerting P Windows IIS Server PSWA Console Access ESCU actions · hunting P Windows SharePoint Spinstall0 GET Request ESCU actions · alerting P Windows SharePoint ToolPane Endpoint Exploitation Attempt ESCU actions · alerting P WordPress Bricks Builder plugin RCE ESCU actions · alerting P WS FTP Remote Code Execution ESCU actions · alerting P Ivanti Sentry Authentication Bypass ESCU actions · alerting P Linux Java Spawning Shell ESCU actions · alerting P Splunk Enterprise Windows Deserialization File Partition ESCU actions · alerting P Splunk RCE via Serialized Session Payload ESCU actions · hunting P Splunk Unauthenticated Log Injection Web Service Log ESCU actions · hunting P Windows Java Spawning Shells ESCU actions · alerting P [LLM] Vulnerable on-prem Exchange OWA exposed to CVE-2026-42897 (TA488 half-click XSS) Bespoke exploit · hunting DSP [LLM] Cisco FMC www account runs package_info.pl on staged /var/tmp/license.tmp (CVE-2026-20316/20079) Bespoke exploit · alerting SΣPDD [LLM] Exposed Rails apps vulnerable to Active Storage libvips file-read (CVE-2026-66066) Bespoke exploit · hunting DSP [LLM] Unauthenticated image-upload burst to Rails Active Storage endpoints (CVE-2026-66066 delivery) Bespoke delivery · hunting SP [LLM] JFrog Artifactory zero-day chain (CVE-2026-65617 et al.) — vulnerable version present Bespoke exploit · alerting DSP [LLM] JFrog Artifactory service process spawning a shell or downloader (RCE exploitation) Bespoke exploit · alerting DSΣPCS [LLM] Artifactory host egress to public internet (package-registry sandbox escape) Bespoke c2 · hunting DSΣPCS [LLM] Prebid-server SSRF payload in OpenRTB2 auction request parameters Bespoke exploit · hunting SΣP [LLM] Prebid-server outbound requests to internal ranges / internal host fan-out (SSRF) Bespoke actions · alerting DSPDDCSCW [LLM] Prebid-server SSRF filter-bypass via encoded internal host in request Bespoke exploit · hunting SΣP [LLM] Ruflo MCP bridge unauthenticated tools/call terminal_execute (RufRoot CVE-2026-59726) Bespoke exploit · alerting SΣPDD [LLM] Ruflo AgentDB memory poisoning via MCP pattern-store write Bespoke actions · hunting SΣPDD [LLM] Inbound network access to Ruflo bridge (3001) / MongoDB (27017) from public source Bespoke delivery · hunting DSPDDCSCW [LLM] Exposure hunt: vCenter auth-bypass + directory-traversal RCE (CVE-2026-59309 / CVE-2026-59310) Bespoke exploit · hunting DSP [LLM] Inbound OT-segment connections from CyberAv3ngers infrastructure (185.82.73.160/28, 135.136.1.133) Bespoke delivery · hunting DSΣPDDCS [LLM] Internet-sourced access to OT/ICS PLCs on EtherNet/IP, Modbus & S7comm ports Bespoke delivery · hunting DSΣP [LLM] Vulnerable Rockwell/Allen-Bradley MicroLogix PLCs exposed to campaign CVEs Bespoke recon · hunting DS [LLM] Coordinated fan-out from CyberAv3ngers infrastructure across multiple OT sites Bespoke actions · alerting DSPDDCS [LLM] Check Point mgmt server contact from CVE-2026-16232 exploitation source IPs Bespoke exploit · hunting DSΣPDDCS [LLM] Check Point SmartConsole admin login via forged application token (CVE-2026-16232) Bespoke exploit · hunting SΣP [LLM] JFrog Artifactory zero-day cluster (CVE-2026-659xx) exposure — pre-7.161.15 with Anonymous Access Bespoke exploit · hunting DS [LLM] Gitea diffpatch endpoint abused twice for add/add hook-drop (CVE-2026-60004) Bespoke exploit · alerting SP [LLM] Gitea git process spawning shell / network tool via planted hook (CVE-2026-60004 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Git server-side hook file written (hooks/post-index-change) - CVE-2026-60004 persistence Bespoke install · alerting DSΣPCS [LLM] Vulnerable Gitea version exposed to CVE-2026-60004 (pre-1.27.1) Bespoke recon · hunting DSP [LLM] Vulnerable @hypequery/clickhouse dependency present (< 2.0.2, CVE-2026-54658) Bespoke exploit · hunting DSΣPDDCS [LLM] @hypequery/clickhouse SQLi: backslash-quote escape bypass in web/API request parameters Bespoke exploit · hunting SΣP [LLM] ClickHouse query_log shows injected SQL from @hypequery escapeValue bypass Bespoke exploit · hunting SPDD [LLM] ClickHouse SQL syntax-error spike from @hypequery/clickhouse injection probing Bespoke exploit · alerting SPDD [LLM] goshs WebDAV --no-delete bypass: blocked DELETE followed by successful MOVE on same path Bespoke exploit · alerting SP [LLM] WebDAV MOVE/COPY write-verb succeeds against goshs artifact server (Overwrite:T destination clobber) Bespoke exploit · hunting SΣP [LLM] Vulnerable goshs SFTP launch: empty-credential basic-auth (-b 'user:' / ':pass') with -sftp and no -fkf Bespoke exploit · alerting DSΣPDDCS [LLM] JFrog Artifactory SSRF egress to non-registry destinations (internet escape) Bespoke c2 · hunting DSΣPCS [LLM] Anonymous access to Artifactory Terraform/Cargo/Ansible remote repositories Bespoke delivery · hunting SPDD [LLM] JFrog Artifactory service process spawning a shell or network tool (RCE) Bespoke exploit · alerting DSΣPCS [LLM] vBulletin CVE-2026-61511 pre-auth RCE via ajax/render/pagenav template request Bespoke exploit · alerting SΣP [LLM] vBulletin web-server process (php-fpm/apache/nginx) spawning OS shell after CVE-2026-61511 Bespoke actions · alerting DSΣPDDCS [LLM] Anomalous Host header on Poweradmin OIDC/SAML/logout endpoints (CVE-2026-54588) Bespoke exploit · hunting SP [LLM] Host header fuzzing burst against Poweradmin auth endpoints from single source Bespoke recon · alerting SP [LLM] Spike of AADSTS50011 redirect_uri mismatch at IdP (poisoned Poweradmin callback) Bespoke exploit · alerting DSPDD [LLM] Self-hosted JFrog Artifactory exposed to OpenAI-credited zero-days CVE-2026-65618/65923/66018 Bespoke exploit · hunting DSP [LLM] Inbound DHCPv6 to odhcpd (UDP 547) from non-link-local source — CVE-2026-53921 exploit reach Bespoke delivery · hunting SP [LLM] LuCI luci-app-commands / ddns command injection with shell metacharacters — root RCE Bespoke exploit · alerting SP [LLM] cgi-io path traversal reading root files — CVE-2026-62947 Bespoke actions · alerting SP [LLM] Vulnerable TeamCity On-Premises exposed to CVE-2026-63077 (unauth agent-polling RCE) Bespoke exploit · hunting DSP [LLM] TeamCity server (java) process spawning an OS command interpreter — CVE-2026-63077 RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Inbound connections from Arista-attributed VeloCloud Orchestrator attacker IPs (CVE-2026-16812) Bespoke delivery · hunting DSΣPCS [LLM] vBulletin CVE-2026-61511 pre-auth RCE via operator-laden pagenav[pagenumber] to ajax/render/pagenav Bespoke exploit · alerting SΣP [LLM] vBulletin web-server process (php-fpm/httpd/w3wp) spawning OS shell — CVE-2026-61511 post-exploitation Bespoke actions · alerting DSΣPDDCS [LLM] Unpatched vBulletin instances exposed to CVE-2026-61511 Bespoke recon · hunting DS [LLM] Fastjson 1.x CVE-2026-16723 exploit payload in inbound JSON (@type + nested JAR / /proc/self/fd) Bespoke exploit · hunting SΣP [LLM] Spring Boot Java process spawning shell/LOLBin child (Fastjson RCE execution) Bespoke install · hunting DSΣPDDCS [LLM] Java (fat-JAR) outbound fetch of remote JAR / SSRF egress to public IP (CVE-2026 Bespoke c2 · hunting DSPDDCS [LLM] GitLab Puma/Ruby worker (running as git) spawns shell or network tool — Oj .ipynb RCE landing Bespoke exploit · hunting DSΣPDDCS [LLM] Outbound reverse-shell egress from GitLab Ruby/Puma worker as git — Oj RCE connect-back Bespoke c2 · hunting DSPCS [LLM] Cl0p hex-named JSP web shell dropped under /Windchill/login/ (CVE-2026-12569) Bespoke install · hunting DSΣPDDCS [LLM] PTC Windchill Java/Tomcat web tier spawning OS command shell (web shell RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Pheditor forced-password-change auth bypass — POST to pheditor.php Bespoke exploit · hunting SΣP [LLM] Web-server / PHP process writes new .php file under webroot (post-Pheditor webshell drop) Bespoke install · hunting DSΣPDDCS [LLM] Budibase REST query published to PUBLIC role (unauth cred-leak enabler) Bespoke exploit · hunting SΣP [LLM] Stacked SQL-injection payload against Budibase datasource query API (multipleStatements) Bespoke exploit · alerting SΣP [LLM] MySQL server (mysqld) writes exfil file via SELECT INTO OUTFILE on Budibase DB host Bespoke actions · hunting DSΣPCS [LLM] OpenAM /authservice CustomCallback ClassName XML — CVE-2026-62379 pre-auth Class.forName RCE Bespoke exploit · alerting SP [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation Bespoke install · alerting DSΣPDDCS [LLM] OpenAM WebAuthn pre-auth Java deserialization payload to /json/authenticate (CVE-2026-62263) Bespoke exploit · alerting SΣP [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Vulnerable @prompty/core package present in node_modules (GHSA-w28w-gp39-m4p6 exposure) Bespoke delivery · hunting DSΣPDDCS [LLM] Velocity.js SSTI RCE payload (constructor.constructor→child_process) in HTTP request Bespoke delivery · alerting SΣP [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] Vulnerable seroval (<=1.5.2) / TanStack Start (<1.167.30) exposure to CVE-2026-59940 deserialization RCE Bespoke exploit · hunting DS [LLM] NodeBB admin-panel access via homepage-setting authorization bypass (first-seen admin API) Bespoke exploit · hunting SP [LLM] NodeBB translation-token template-injection XSS in web request URI Bespoke exploit · alerting SΣP [LLM] NodeBB ActivityPub private-message disclosure via unsigned GET enumeration Bespoke actions · alerting SP [LLM] Unauthenticated NodeBB ActivityPub category-outbox private-content disclosure Bespoke actions · hunting SΣP [LLM] NodeBB federation actor spoofing — new peer POSTing to ActivityPub inbox (CVE-2026-58593 / vote inflation) Bespoke exploit · hunting SP [LLM] Vulnerable stock Redis version exposed (6.2.22/7.4.9/8.6.4/8.8.0 — July 2026 RESTORE RCE) Bespoke exploit · hunting DSP [LLM] redis-server spawns a shell/interpreter (system() from Redis RCE chain) Bespoke exploit · alerting DSΣPCS [LLM] Auth.js fail-open exploited: protected routes served 200/302 during an active auth-error window Bespoke exploit · hunting SP [LLM] Unpatched Zimbra Collaboration exposed to CVE-2025-66376 (Void Blizzard target) Bespoke exploit · hunting DS [LLM] wp2shell SQLi via author__not_in REST parameter (CVE-2026-60137) Bespoke exploit · alerting SΣP [LLM] Gitea PR-update endpoint enumeration across multiple repositories (CVE-2026-58443) Bespoke actions · hunting SP [LLM] Vulnerable Gitea Docker version exposed to CVE-2026-20896 (auth bypass) Bespoke recon · hunting DS [LLM] Gitea webhook/migration SSRF reaching cloud metadata endpoints (IMDS / Azure WireServer) Bespoke actions · hunting DSΣPDDCS [LLM] Gitea process egress to SSRF allow-list bypass internal ranges (CGNAT / 172.32.0.0/11) Bespoke recon · hunting DSΣPDDCS [LLM] Vulnerable Gitea version exposed to CVE-2026-22874 SSRF (pre-1.26.4) Bespoke weapon · hunting DS [LLM] Vitest Browser Mode / test API (node.exe) accepting inbound connections on 63315/51204 from non-loopback host Bespoke exploit · hunting DSΣPDDCS [LLM] MSSQL sqlservr.exe spawning OS shell via xp_cmdshell (XEntry Team) Bespoke exploit · alerting DSΣPDDCS [LLM] LightRAG destructive document ops post-bypass (DELETE /documents, clear_cache, unauth upload) Bespoke actions · alerting SΣP [LLM] WordPress wp2shell batch REST API pre-auth RCE exploitation (CVE-2026-63030/60137) Bespoke exploit · alerting SΣP [LLM] Web server daemon (php-fpm/apache/nginx/w3wp) spawning a shell or network tool — wp2shell post-exploit code execution Bespoke exploit · alerting DSΣPDDCS [LLM] Siemens RUGGEDCOM ROX II devices exposed to CVE-2025-40947/48/49 (firmware < V2.17.1) Bespoke exploit · alerting DS [LLM] Pheditor terminal RCE: web-server/PHP process spawns shell (CVE-2026-55579) Bespoke exploit · alerting DSΣPDDCS [LLM] Pheditor file-upload abuse: web-server process writes new .php webshell Bespoke install · alerting DSΣPDDCS [LLM] Pheditor default-credential exploitation traffic: POST to /pheditor.php from external source Bespoke delivery · hunting SΣP [LLM] EnvoyExtensionPolicy Lua with double-slash path traversal to secrets (CVE-2026-53713) Bespoke exploit · alerting SΣPDD [LLM] EnvoyExtensionPolicy Lua invoking os/io/debug file primitives Bespoke exploit · hunting SΣPDD [LLM] Anomalous EnvoyExtensionPolicy submitter / suspicious policy name Bespoke delivery · hunting SΣPDD [LLM] Vulnerable Envoy Gateway version exposed to CVE-2026-53713 Bespoke recon · hunting DS [LLM] Unauthenticated access to MantisBT admin/install.php on a production host (CVE-2026-52847) Bespoke recon · hunting SΣP [LLM] Credential-phishing form injection via reflected XSS in MantisBT install.php (CVE-2026-52881) Bespoke delivery · alerting SΣP [LLM] Meta open-redirect injection via reflected XSS in MantisBT install.php (CVE-2026-52881) Bespoke delivery · alerting SΣP [LLM] Broad reflected HTML/XSS payload tokens in MantisBT install.php query string Bespoke exploit · hunting SΣP [LLM] MantisBT self-registration (signup.php) followed by SOAP replay to mantisconnect.php from same source Bespoke exploit · hunting SP [LLM] FacturaScripts upload endpoint: path-traversal sequence in multipart filename Bespoke exploit · alerting SΣP [LLM] FacturaScripts: PHP/.htaccess web-shell written into web-served Dinamic/Assets or node_modules Bespoke install · alerting DSΣPDDCS [LLM] FacturaScripts RCE chain: .htaccess handler-remap override plus payload drop in same asset dir Bespoke exploit · alerting DSPCS [LLM] n8n-MCP vulnerable multi-tenant config exposure (ENABLE_MULTI_TENANT without version-tool mitigation) Bespoke exploit · hunting SP [LLM] Anyquery server mode bound to all interfaces (exposed unauthenticated MySQL port) Bespoke delivery · hunting DSΣPDDCS [LLM] Inbound connection to Anyquery listener from a public IP Bespoke delivery · hunting DSPCS [LLM] Anyquery process writing files to cron/webroot/SSH persistence paths (ATTACH DATABASE AFW) Bespoke install · alerting DSΣPCS [LLM] ATTACH DATABASE statement targeting persistence paths in Anyquery query logs Bespoke exploit · hunting SPDD [LLM] FacturaScripts CVE-2026-45262 SQLi: parenthesis-bypass in REST API filter[] key Bespoke exploit · alerting SΣP [LLM] FacturaScripts filter[] SQLi column-count / schema enumeration (burst probing) Bespoke exploit · hunting SP [LLM] Kimai authenticated session activity with no preceding form-login POST (forged remember-me cookie) Bespoke exploit · hunting SP [LLM] Kimai forged Symfony login-link request (user+expires+hash signed URL) to super_admin Bespoke exploit · hunting SΣP [LLM] DIRAC FileCatalog checkDataset SQL injection carrying Python eval gadget (CVE-2026-61667) Bespoke exploit · hunting SPDD [LLM] DIRAC FileCatalog service Python process spawns shell or recon binary (eval RCE) Bespoke install · alerting DSΣPDDCS [LLM] DIRAC ReqManager service (CVE-2026-45579) spawning a shell or recon/egress binary Bespoke exploit · alerting DSΣP [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) Bespoke exploit · alerting DSΣPCS [LLM] FileBrowser reverse-proxy bypass: direct external access to exposed port 8085 Bespoke delivery · alerting DSΣPDDCS [LLM] FileBrowser instance configured with auth.method=proxy (exploitable-config exposure) Bespoke recon · hunting DSΣPDDCS [LLM] Authorizer /authorize implicit-flow token leak to off-origin redirect_uri (CVE-2026-54072) Bespoke exploit · alerting SΣP [LLM] Authorizer unauthenticated /graphql client_id reconnaissance (CVE-2026-54072 pre-exploit) Bespoke recon · hunting SΣP [LLM] Authorizer /authorize redirect_uri iteration — multiple distinct targets from one source Bespoke exploit · alerting SP [LLM] Spike in Authorizer /authorize 302 redirects to off-origin hosts (bulk token exfiltration) Bespoke actions · hunting SP [LLM] YesWiki Bazar CalcField eval() RCE — dangerous PHP functions in form-save request Bespoke exploit · alerting SΣP [LLM] YesWiki CalcField ReDoS/stack-overflow DoS — deeply nested parentheses payload Bespoke actions · alerting SΣP [LLM] YesWiki post-RCE — php-fpm/apache spawns Unix shell or recon binary (www-data) Bespoke install · alerting DSΣPDDCS [LLM] YesWiki CalcField exploit attempts — PHP parse/fatal errors from CalcField.php in syslog Bespoke exploit · hunting SPDD [LLM] YesWiki BazarImportAction object-injection exploit request (CVE-2026-52777) Bespoke exploit · alerting SΣP [LLM] Base64 PHP-serialized-object payload in importfiche POST body Bespoke exploit · alerting SP [LLM] YesWiki web-server process spawning an OS shell (deserialization RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] YesWiki unauthenticated erasespamedcomments page-deletion invocation (CVE-2026-52766) Bespoke exploit · alerting SΣP [LLM] Unpatched Ruckus/ASUS edge devices exposed to UAT-7810 exploit CVEs Bespoke exploit · hunting DSP [LLM] Nuclio CronJob container args carry injected shell (CVE-2026-52831 header/body OS command injection) Bespoke exploit · alerting SPDD [LLM] SSRF via Better Auth SSO provider registration to internal endpoints (CVE-2026-53513) Bespoke exploit · hunting SΣP [LLM] Better Auth OIDC discovery probe followed by token/registration endpoint access (CVE-2026-53512/53513 recon) Bespoke recon · hunting SP [LLM] EGroupware CVE-2026-27823 arbitrary file read via importexport download path traversal Bespoke exploit · alerting SΣP [LLM] EGroupware header.inc.php overwritten by web process (CVE-2026-27823 RCE persistence) Bespoke install · alerting DSΣPCS [LLM] 9router credential dump via GET /api/settings/database (CVE-2026-55500) Bespoke actions · alerting SΣP [LLM] 9router export-then-import chain from same source (CVE-2026-55500 takeover) Bespoke actions · alerting SP [LLM] 9router token brute-force burst against /api/settings/database (CVE-2026-55500) Bespoke exploit · alerting SP [LLM] Cypher injection primitives in Langroid LLM prompt / inbound HTTP input Bespoke exploit · hunting SPDD [LLM] Neo4j executes attacker-primitive Cypher (apoc.*, dbms.*, LOAD CSV) via query.log Bespoke exploit · alerting SΣPDD [LLM] Neo4j server outbound egress to public IP (LOAD CSV / apoc.load SSRF) Bespoke c2 · hunting DSPDDCS [LLM] Rocket.Chat Livechat file-upload ID enumeration sweep (ObjectId harvest) Bespoke actions · alerting SP [LLM] Rocket.Chat anonymous Livechat visitor bootstrap chained to file-upload access Bespoke exploit · alerting SP [LLM] Rocket.Chat file-upload request carrying Livechat auth params (IDOR signature) Bespoke exploit · hunting SΣP [LLM] Twig SSTI markers in request-controlled fields against Craft/Formie public forms Bespoke exploit · hunting SΣP [LLM] Active Twig RCE gadget strings in Craft/Formie HTTP request inputs Bespoke exploit · alerting SΣP [LLM] Craft/PHP/IIS web worker spawning a command shell (Formie SSTI RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] Forged unsigned (alg:none) JWT Bearer token reaching Apache Camel route (CVE-2026-53913) Bespoke exploit · alerting SP [LLM] Vulnerable camel-keycloak version exposed (CVE-2026-53913 affected range) Bespoke recon · hunting DS [LLM] Apache Camel DNS SSRF: inbound HTTP request carrying dns.server / dns.name control headers Bespoke delivery · hunting SΣP [LLM] Apache Camel gridfs.* control-header injection inbound (CVE-2026-48204 exploit) Bespoke exploit · hunting SΣPDD [LLM] phpBB CVE-2026-48611 auth bypass via login_link auth_provider=apache Bespoke exploit · alerting SΣP [LLM] phpBB CVE-2026-48611 post-exploit ACP access from exploiting IP Bespoke actions · alerting SP [LLM] HTTP Basic Authorization header sent to phpBB login_link endpoint Bespoke exploit · hunting SP [LLM] 9router unauthenticated MCP / cli-tools route RCE via process spawn — CVE-2026-46339 Bespoke exploit · alerting DSΣPCS [LLM] GravitLauncher LaunchServer secret read via unauth path traversal (ecdsa_id/legacySalt/LaunchServer.json) Bespoke exploit · alerting SΣP [LLM] LaunchServer path-traversal exploit signature: request-target without leading slash / %2e%2e on port 9274 Bespoke exploit · alerting DSΣPCS [LLM] fast-mcp-telegram traversal token in request URL (URL-auth middleware) CVE-2026-52830 Bespoke exploit · alerting SP [LLM] Unauthenticated POST to 9router /api/tunnel/tailscale-install (CVE-2026-59800 auth bypass) Bespoke exploit · alerting DSΣP [LLM] Web-server process writes PHP file into Mautic config/cache/media/logs (zip-slip landing) Bespoke install · alerting DSΣPCS [LLM] Mautic campaign import ZIP upload — POST to campaign import endpoint Bespoke delivery · hunting SP [LLM] Mautic Twig SSTI RCE: PHP/web process spawns OS shell (CVE-2026-9558) Bespoke exploit · alerting DSΣPDDCS [LLM] Weaponized Twig theme written under Mautic themes/ by web process (CVE-2026-9558) Bespoke install · hunting DSΣPDDCS [LLM] Affected zebrad (<= v4.4.1) exposure to P2SH sigop consensus-split (CVE-2026-52735) Bespoke exploit · hunting DSP [LLM] zebrad node process execution at vulnerable version (CVE-2026-52735) Bespoke exploit · hunting DSΣPDDCS [LLM] CVE-2026-50027 unauthenticated write to mcp-memory-service /api/documents/upload Bespoke install · hunting SΣP [LLM] CVE-2026-50027 auth-bypass fingerprint: 401 on /api/memories then 200 on /api/documents from same source Bespoke exploit · alerting SP [LLM] CVE-2026-50027 full exploit chain: probe, write, bulk-read, delete from one source in 15m Bespoke actions · alerting SP [LLM] Web shell execution: web server process spawning command interpreters Bespoke exploit · alerting DSΣPDDCS [LLM] Ghost x-ghost-preview cache-poisoning header in inbound HTTP requests (CVE-2026-53943) Bespoke delivery · hunting SΣPDD [LLM] Unauthenticated x-ghost-preview request to cached Ghost frontend (CVE-2026-53943 precondition) Bespoke exploit · alerting SP [LLM] Ghost x-ghost-preview request carrying XSS payload markers (CVE-2026-53943 execution) Bespoke exploit · alerting SΣPDD [LLM] Rancher Manager assets vulnerable to CVE-2026-41052 (PSA privilege-escalation exposure) Bespoke recon · hunting DS [LLM] Rancher /v3/import authImage YAML injection via URL-encoded newlines (CVE-2026-44939) Bespoke exploit · alerting SΣP [LLM] Rancher /v3/import registration-token enumeration or cross-source reuse Bespoke recon · hunting SP [LLM] FortiGate jsconsole / loopback admin login (CVE-2024-55591 auth-bypass exploitation) Bespoke exploit · alerting SP [LLM] Exposed phpBB instances vulnerable to CVE-2026-48611 / 48612 / 29199 auth bypass Bespoke exploit · hunting DSP [LLM] phpBB ACP access from a source IP with no prior login (CVE-2026-48611 session hijack) Bespoke exploit · hunting SP [LLM] phpBB password-reset host-header poisoning (CVE-2026-29199) Bespoke exploit · hunting SP [LLM] phpBB OAuth account-binding CSRF via cross-site request to /user/oauth/authenticate/ (CVE-2026-48612) Bespoke exploit · hunting SP [LLM] Thymeleaf SpEL tab-character sandbox bypass payload in HTTP request (CVE-2026-40478) Bespoke exploit · alerting SΣPDD [LLM] Java/Tomcat process writes .jsp webshell file to disk (CVE-2026-40478 post-exploit drop) Bespoke install · alerting DSΣPDDCS [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Bespoke actions · alerting DSΣPDDCS [LLM] Qinglong CVE-2026-3965 auth bypass via /open/user/init credential reset Bespoke exploit · alerting DSΣPDDCS [LLM] Qinglong CVE-2026-4047 case-mismatch auth bypass via /aPi/system/command-run Bespoke exploit · alerting DSΣPDD [LLM] Mailcow Autodiscover endpoint receives unauthenticated XSS payload (GHSA-f9xf-vc72-rcgm) Bespoke delivery · alerting SPDD [LLM] Mailcow login with HTML/JS injected into X-Real-IP header (GHSA-jprq-w83q-q62h) Bespoke delivery · alerting SPDD [LLM] Hoppscotch device-login open redirect token theft via localhost.* / sslip.io bypass Bespoke exploit · alerting DSΣPDDCS [LLM] Hoppscotch Mock Server stored XSS via GraphQL updateRESTUserRequest content-type override Bespoke exploit · hunting DSPDD [LLM] Hoppscotch cross-team request injection via moveRequest GraphQL with null nextRequestID Bespoke exploit · hunting SPDD [LLM] BodySnatcher (CVE-2025-12420) ServiceNow Virtual Agent bot/integration exploit Bespoke exploit · alerting SΣP [LLM] BodySnatcher (CVE-2025-12420) — Hardcoded 'servicenowexternalagent' Token Observed in HTTP Traffic Bespoke exploit · alerting DSΣPDDCS [LLM] ServiceNow Virtual Agent Invocation of Hidden AIA-Agent Invoker AutoChat Topic (CVE-2025-12420) Bespoke exploit · alerting DSPDDCS [LLM] Vulnerable react-server-dom-* package versions (CVE-2025-55182) in workload inventory Bespoke recon · hunting DSPDDCS [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server Bespoke exploit · alerting DSΣPDDCS [LLM] Anomalous POST to Next.js Server Action / RSC endpoint with 5xx error clustering Bespoke exploit · alerting DSPDDCS [LLM] Next.js CVE-2025-29927 middleware bypass via x-middleware-subrequest header Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Spark CVE-2022-33891 doAs command injection — shell spawned by Spark JVM running 'id -Gn' with metacharacters Bespoke exploit · alerting DSΣPDDCS [LLM] ImageMagick 'convert -resize' command injection via sh -c in Go web app Bespoke exploit · hunting DSΣPDDCS [LLM] Inbound UDP/631 (CUPS IPP discovery) from external network Bespoke delivery · hunting DSΣPDDCS [LLM] Linux assets with vulnerable CUPS packages and external exposure (CVE-2024-47175/76/77/076) Bespoke recon · hunting DSPDDCS [LLM] Log4Shell JNDI exploitation string in inbound HTTP requests (CVE-2021-44228) Bespoke exploit · alerting SΣP [LLM] Log4Shell outbound JNDI callback from Java process to LDAP/RMI (CVE-2021-44228) Bespoke c2 · alerting DSΣPDDCS [LLM] Spring4Shell classLoader payload in inbound HTTP request (CVE-2022-22965) Bespoke exploit · alerting SΣP [LLM] Spring4Shell JSP webshell drop by Tomcat/Java into webapps (CVE-2022-22965) Bespoke install · alerting DSΣPDDCS [LLM] Exposure: hosts running python-multipart ≤0.0.6 / FastAPI ≤0.109.0 vulnerable to CVE-2024-24762 ReDoS Bespoke exploit · hunting DSP [LLM] Vulnerable HTTP/2 server inventory: CONTINUATION flood CVE cluster (CVE-2024-27316 et al.) Bespoke recon · hunting DSP [LLM] HTTP/2 server crash-loop on internet-facing host (CONTINUATION flood DoS exploitation signal) Bespoke actions · alerting DSPDDCS [LLM] Web-app runtime egress to AWS IMDS endpoint (169.254.169.254) — SSRF credential theft Bespoke actions · hunting DSΣPDDCS [LLM] Boolean-tautology SQL injection against Node.js/Express search endpoint Bespoke exploit · hunting SΣP [LLM] Vulnerable Jinja2 < 3.1.3 inventory pivot for CVE-2024-22195 (xmlattr XSS) Bespoke recon · hunting DSP [LLM] Jinja2 xmlattr XSS exploitation attempt in HTTP request parameters (CVE-2024-22195) Bespoke exploit · alerting SΣP [LLM] Struts CVE-2023-50164 path-traversal upload — HTTP exploit attempt Bespoke exploit · alerting DSΣPDD [LLM] Tomcat/Java process writes .jsp/.jspx webshell into webapp directory Bespoke install · alerting DSΣPDDCS [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) Bespoke actions · alerting DSΣPDDCS [LLM] PHP web-server process initiating outbound TCP (fsockopen reverse shell to attacker) Bespoke c2 · alerting DSΣPCS [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) Bespoke exploit · alerting DSΣPDDCS [LLM] Browser extension folder write at vulnerable React DevTools 4.27.8 / Vue.js devtools 6.5.0 Bespoke exploit · hunting DSΣPDDCS [LLM] Curl invoked with SOCKS5-hostname resolution (CVE-2023-38545 exploit precondition) Bespoke exploit · hunting DSΣPDDCS [LLM] Vulnerable libcurl/curl version present on host (CVE-2023-38545) Bespoke recon · hunting DS [LLM] Hosts exposed to libwebp heap overflow CVE-2023-4863 / CVE-2023-5129 (TVM) Bespoke weapon · alerting DSP [LLM] Vulnerable SnakeYAML <2.0 present (CVE-2022-1471 unsafe deserialization) Bespoke exploit · hunting DSP [LLM] JVM (java/javaw) spawning OS command interpreter — SnakeYAML gadget RCE outcome Bespoke exploit · hunting DSΣPDDCS [LLM] JVM outbound fetch of remote class/JAR to public host — URLClassLoader gadget Bespoke delivery · hunting DSPDDCS [LLM] node-serialize / serialize-to-js deserialization RCE payload marker `_$$ND_FUNC$$_` in web request Bespoke exploit · alerting SP [LLM] Node.js process spawning a command interpreter (deserialization RCE child_process exec) Bespoke exploit · alerting DSΣPDDCS [LLM] Ruby/Rails app server spawning a Unix shell (post-deserialization RCE) Bespoke exploit · alerting DSΣPCS [LLM] Exposure hunt: hosts running Spring Security vulnerable to CVE-2022-31692 forward/include auth bypass Bespoke recon · hunting DSP [LLM] SnakeYAML deserialization gadget tags in HTTP request (CVE-2022-1471) Bespoke exploit · alerting SΣP [LLM] Java process (java.exe/javaw.exe) spawning OS command shell — SnakeYAML RCE Bespoke exploit · hunting DSΣPDDCS [LLM] Java process outbound LDAP/RMI to fetch remote class — SnakeYAML JNDI gadget Bespoke c2 · alerting DSΣPDDCS [LLM] Pistache CVE-2022-26068 path traversal reading /etc/passwd via /doc/../ Bespoke exploit · alerting SΣP [LLM] Pistache binary theft via /doc/../../proc/self/exe path traversal Bespoke actions · alerting SΣP [LLM] curl --path-as-is traversal command exfiltrating /proc/self/exe or /etc/passwd Bespoke exploit · alerting DSΣPDDCS [LLM] URL-encoded directory traversal (%2e%2e) against node 'st' static-file route (CVE-2014-3744) Bespoke exploit · hunting SΣP [LLM] Vulnerable OpenSSL 3.0.0–3.0.6 exposure (CVE-2022-3602 / CVE-2022-3786, 'SpookySSL') Bespoke exploit · hunting DSP [LLM] Text4Shell (CVE-2022-42889) Commons Text interpolation payloads in inbound web requests Bespoke exploit · alerting SΣP [LLM] Java/JVM spawning OS shell after Text4Shell (CVE-2022-42889) script-engine RCE Bespoke install · alerting DSΣPDDCS [LLM] Git argument injection via --upload-pack option spawned by web-app runtime Bespoke exploit · alerting DSΣPDDCS [LLM] Mercurial argument injection via --config alias/hooks or --debugger from app runtime Bespoke exploit · alerting DSΣPDDCS [LLM] git/hg spawning a shell as child of a web-app runtime (argument-injection RCE evidence) Bespoke exploit · hunting DSPDDCS [LLM] Server application runtime spawning shell with /dev/tcp redirection (RCE to reverse shell) Bespoke exploit · alerting DSΣPCS [LLM] Apache Commons Configuration interpolation RCE payload in HTTP requests (CVE-2022-33980) Bespoke exploit · hunting SΣP [LLM] Java (ProcessBuilder) spawning shell/LOLBin child — Commons Config interpolation RCE Bespoke install · alerting DSΣPDDCS [LLM] Java process fetching first-seen external URL/DNS — Commons Config url/dns lookup (CVE-2022-33980) Bespoke c2 · hunting DSPDDCS [LLM] Prototype pollution attempt via __proto__ in URL query string (CVE-2021-23682, litespeed.js/appwrite) Bespoke exploit · hunting SΣP [LLM] Node.js web process overwriting application .js service file (GraphQL path-traversal file write) Bespoke exploit · hunting DSΣPCS [LLM] Spring4Shell classLoader property injection via dirContext.docBase (Glassfish/Payara/Tomcat) Bespoke exploit · alerting SΣP [LLM] Web path-traversal arbitrary file read via '../' in static-file URL (Crow CVE-2021-23514) Bespoke exploit · alerting SΣP [LLM] Arbitrary file write via '../' in upload 'name' parameter (Mongoose CVE-2022-25299) Bespoke install · alerting DSΣPCS [LLM] Spring4Shell (CVE-2022-22965) classLoader pipeline injection / JSP webshell call in web logs Bespoke exploit · alerting SΣP [LLM] Tomcat/Java JVM spawning command shell (Spring4Shell webshell command execution) Bespoke actions · hunting DSΣPDDCS [LLM] Spring4Shell (CVE-2022-22965) exploit: class.module.classLoader ClassLoader manipulation in HTTP request Bespoke exploit · alerting SΣP [LLM] Tomcat/Java writes JSP webshell into webapps (Spring4Shell post-exploit drop) Bespoke install · alerting DSΣPDDCS [LLM] Java/Tomcat spawns command shell or download tool (Spring4Shell RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] Outbound connection to Spring4Shell Mirai staging IPs (107.174.133.167 / 194.31.98.186) Bespoke c2 · hunting DSΣPDDCSCW [LLM] HTTP request to executable PHP inside dompdf font cache (CVE-2022-28368 RCE trigger) Bespoke exploit · alerting SΣP [LLM] Magento CVE-2022-24086/24087 TrojanOrders checkout exploitation from known attacker IP Bespoke exploit · alerting SΣP [LLM] Magento webshell drop (health_check.php / pub-media PHP) written by web-server process Bespoke install · alerting DSΣPCS [LLM] Magento php-fpm/web-server spawning shell or download utility (CVE-2022-24086 RCE) Bespoke exploit · hunting DSΣPCS [LLM] Outbound or inbound connection to TrojanOrders C2/source IP 45.134.20.11 Bespoke c2 · hunting DSΣPDDCS [LLM] Magento CVE-2022-24086 template-directive injection in web requests (getTemplateFilter RCE) Bespoke exploit · hunting SΣP [LLM] Magento web process (w3wp/php-fpm/php-cgi) spawning OS shell — CVE-2022-24086 RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Network activity involving CVE-2022-24086 attacker IP 45.134.20.11 Bespoke c2 · hunting DSΣPDDCSCW [LLM] Celery worker (Python) spawning a shell — CVE-2021-23727 stored command injection Bespoke exploit · hunting DSΣPCS [LLM] Hosts running Celery < 5.2.2 vulnerable to CVE-2021-23727 Bespoke recon · hunting DS [LLM] Log4Shell JNDI lookup string in inbound web request (CVE-2021-44228 exploitation) Bespoke exploit · alerting SP [LLM] Java/Tomcat application server spawning command shell or netcat (Log4Shell RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Java process making outbound LDAP/RMI callout to public host (JNDI egress) Bespoke c2 · hunting DSΣPDDCS [LLM] Log4j logging configuration file modified (CVE-2021-44832 JDBC Appender precondition) Bespoke weapon · hunting DSΣPDDCS [LLM] Java process outbound LDAP/RMI egress (CVE-2021-44832 remote JNDI data source load) Bespoke exploit · alerting DSΣPDDCS [LLM] Vulnerable Apache Log4j inventory exposed to CVE-2021-44832 (pre-2.17.1/2.12.4/2.3.2) Bespoke recon · hunting DSP [LLM] Log4j CVE-2021-45046 JNDI localhost-bypass payload (${jndi:...127.0.0.1#...}) in web requests Bespoke exploit · alerting DSΣPCS [LLM] Log4Shell RCE execution: java/javaw spawning a shell or LOLBin Bespoke exploit · alerting DSΣPDDCS [LLM] Log4Shell JNDI class fetch: java process outbound to LDAP/RMI ports Bespoke c2 · alerting DSΣPDDCS [LLM] Exposure: hosts running Log4j versions vulnerable to CVE-2021-45046 Bespoke recon · hunting DSP [LLM] Log4Shell JNDI lookup injection string in HTTP requests / process cmdline (${jndi:ldap}) Bespoke exploit · alerting DSΣPDDCS [LLM] Java process making outbound LDAP/RMI connection (Log4Shell second-stage class fetch) Bespoke delivery · hunting DSΣPDDCS [LLM] Java/Tomcat process spawning OS shell (Log4Shell Runtime.exec post-exploitation) Bespoke install · alerting DSΣPDDCS [LLM] Log4Shell JNDI lookup string in inbound HTTP request (URI / User-Agent / headers) Bespoke exploit · alerting SΣP [LLM] Java (java.exe/javaw.exe) spawning shell or LOLBin — Log4Shell post-exploitation Bespoke install · alerting DSΣPDDCS [LLM] Java process outbound to LDAP/RMI/DNS callback port — Log4Shell JNDI fetch Bespoke c2 · alerting DSΣPDDCS [LLM] Log4Shell JNDI lookup string in inbound web request (CVE-2021-44228 exploitation) Bespoke exploit · alerting SΣP [LLM] Java process outbound LDAP/RMI to public IP (Log4Shell JNDI callback) Bespoke c2 · hunting DSΣPDDCS [LLM] Java/Tomcat process spawning shell, curl or wget (Log4Shell RCE follow-on) Bespoke install · alerting DSΣPDDCS [LLM] Prototype pollution / type-confusion payload in web request (__proto__, constructor[prototype]) Bespoke exploit · hunting SΣP [LLM] CVE-2020-9484 Tomcat session deserialization: JSESSIONID path-traversal in HTTP request Bespoke exploit · alerting SΣP [LLM] Tomcat/Java server process spawning an OS command shell (CVE-2020-9484 RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] Attacker-staged .session deserialization payload written outside Tomcat's session store Bespoke delivery · hunting DSΣPDDCS [LLM] SuiteCRM PHAR deserialization via case-mixed phar:// wrapper in admin request Bespoke exploit · alerting SΣP [LLM] Direct HTTP 200 to SuiteCRM /upload or /files (post-.htaccess-deletion code exec) Bespoke actions · hunting SΣP [LLM] ImageMagick convert spawning shell/LOLBin child (ImageTragick CVE-2016-3714 RCE) Bespoke exploit · alerting DSΣPCS [LLM] Semicolon GET parameter cloaking in web/proxy logs (cache poisoning, CVE-2021-23336 / CVE-2020-28473) Bespoke exploit · hunting SΣP [LLM] Assets exposed to cache-poisoning CVEs (Python parse_qsl CVE-2021-23336 / Bottle CVE-2020-28473) Bespoke recon · hunting DSP [LLM] systeminformation inetChecksite curl argument injection (CVE-2020-7752) Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js (Express) process spawning a command shell — express-fileupload prototype-pollution RCE outcome Bespoke exploit · hunting DSΣPDDCS [LLM] Prototype-pollution payload (__proto__ / constructor.prototype) in inbound web requests to Express app Bespoke exploit · hunting SΣP [LLM] Exposure: hosts running express-fileupload vulnerable to CVE-2020-7699 Bespoke exploit · hunting DSP [LLM] Celery task injected into Apache Airflow message broker (unacked queue / execute_command) Bespoke delivery · alerting DSΣPDDCS [LLM] Apache Airflow Celery worker spawns non-airflow child (command-injection RCE, CVE-2020-11981) Bespoke exploit · alerting DSΣPCS [LLM] Apache Airflow task run with --pickle flag (pickle deserialization, CVE-2020-11982) Bespoke exploit · hunting DSΣPDDCS [LLM] Hosts exposed to Apache Airflow Celery broker RCE (CVE-2020-11981 / CVE-2020-11982) Bespoke recon · hunting DSP [LLM] GET request carrying a body / Content-Length — HTTP request smuggling (CL:CL) precursor Bespoke exploit · hunting SP [LLM] Front-end/back-end stack exposed to request-smuggling CVEs (nginx CVE-2020-12440, Werkzeug CVE-2019-16786) Bespoke exploit · alerting DSP [LLM] Ghostcat: inbound AJP (TCP/8009) connections from untrusted/public sources to Tomcat Bespoke exploit · hunting DSΣPDDCS [LLM] Ghostcat RCE: Tomcat/java process spawning a command shell (JSP webshell execution) Bespoke exploit · hunting DSΣPDDCS [LLM] Ghostcat exposure: assets running Tomcat versions vulnerable to CVE-2020-1938 Bespoke exploit · hunting DSP [LLM] Access to exposed Elector '/get-admin-users' credential-leaking API endpoint Bespoke exploit · alerting SΣP [LLM] Node.js launched with --insecure-http-parser flag (strict HTTP parsing disabled) Bespoke exploit · alerting DSΣPDDCS [LLM] Hosts exposed to Node.js Feb-2020 HTTP/TLS CVEs (CVE-2019-15604/15605/15606) Bespoke recon · hunting DS [LLM] Sequelize ORM JSON-path SQLi exploitation via ')) AS DECIMAL)' cast-break (CVE-2019-10748) Bespoke exploit · alerting SΣP [LLM] Exposure: jackson-databind <=2.9.9.2 / Spring Boot 2.1.7 vulnerable to CVE-2019-14379/14439 deserialization RCE Bespoke exploit · alerting DSP [LLM] Java/Spring Boot process spawning a shell — possible jackson-databind deserialization RCE Bespoke exploit · hunting DSΣPDDCS [LLM] Webmin password_change.cgi unauthenticated command injection exploit attempt (CVE-2019-15107) Bespoke exploit · hunting SΣP [LLM] Webmin RCE: miniserv/password_change.cgi spawning reverse shell (CVE-2019-15107) Bespoke exploit · alerting DSΣPDDCS [LLM] Vulnerable lodash (CVE-2019-10744 prototype pollution) present in software inventory Bespoke weapon · alerting DSP [LLM] Prototype pollution payload (__proto__ / constructor.prototype) in inbound web requests Bespoke exploit · hunting SΣP [LLM] Vulnerable urllib3 (<= 1.24.2 / CVE-2019-11236) present in software inventory Bespoke weapon · hunting DS [LLM] CRLF / HTTP-header injection in URL query string (urllib3 CVE-2019-11236 PoC shape) Bespoke exploit · hunting SΣP [LLM] jQuery prototype pollution payload (__proto__) in inbound HTTP request (CVE-2019-11358) Bespoke exploit · hunting SΣP [LLM] URL-encoded directory traversal (%2e%2e) against Node 'st' static file server Bespoke exploit · hunting SΣP [LLM] Successful sensitive-file disclosure via st traversal (/etc/passwd, package-lock.json) Bespoke actions · alerting SΣP [LLM] Anonymous access to Kubernetes aggregated API (CVE-2018-1002105 exploit surface) Bespoke exploit · hunting SΣPDDCW [LLM] Zip Slip arbitrary file overwrite by archive-handling runtime (java/python) via path traversal Bespoke exploit · hunting DSΣPDDCS [LLM] Exposure: hosts running Zip Slip-vulnerable Apache Storm / Hadoop (CVE-2018-8008 / CVE-2018-8009) Bespoke exploit · alerting DSP [LLM] Apache Struts web app (java/Tomcat) spawning OS shell or recon — post-exploit RCE (CVE-2017-5638 / CVE-2017-9805) Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Struts OGNL / XStream exploit payload in WAF & web logs (CVE-2017-5638 + CVE-2017-9805) Bespoke exploit · alerting SP [LLM] Dust.js qs type-manipulation RCE payload in web request query string Bespoke exploit · alerting SΣP [LLM] qs prototype-override bypass exploit attempt in HTTP query string (CVE-2017-1000048) Bespoke exploit · alerting SΣP [LLM] ImageMagick binary spawning shell/recon process (ImageTragick CVE-2016-3714 delegate RCE) Bespoke exploit · hunting DSΣPCS [LLM] ImageMagick binary making outbound network connection (ImageTragick URL/HTTPS coder SSRF) Bespoke c2 · hunting DSPCS

Articles citing this technique (2549)