Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Initial Access/ T1190

T1190Exploit Public-Facing Application

T1190 — Exploit Public-Facing Application is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 459 detection use cases covering it and 2574 threat-intel articles citing it.

Initial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
459Use cases
2574Articles
0Sub-techniques
1Tactic

Use cases covering this technique (459)

Authentication not detected on admin API endpoint Internal delivery · hunting DD Excessive resource consumption of third-party API Internal actions · hunting DD JWT authentication bypass attempt Internal delivery · alerting DD Local File Inclusion (LFI) exploited Internal delivery · alerting DD Spring4Shell RCE attempts (CVE-2022-22963) Internal delivery · alerting DD AWS S3 bucket ACL / policy made public Internal actions · alerting DDCW Command injection exploited (WAF detection) Internal delivery · alerting DD Distributed credential-stuffing campaign Internal delivery · alerting DD Log4Shell RCE attempts (CVE-2021-44228) Internal delivery · alerting DD SQL injection exploited (WAF detection) Internal delivery · alerting DD SSRF exploited (WAF detection) Internal delivery · alerting DD Asset exposure — vulnerability matches article CVE(s) Internal recon · alerting DSP [WEEKLY] AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process Internal exploit · alerting DSΣPDDCS [WEEKLY] AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) Internal exploit · alerting DSΣPDDCS [WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Gitea Service Account Post-Exploitation: git/gitea Spawning Interpreters or Egressing to Cloud Metadata Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-facing server process spawns interpreter then beacons to first-seen external host within 5 minutes Internal install · alerting DSPDD [WEEKLY] Internet-Facing Service Daemon Spawns Shell or Ingress Tool Then Beacons Out Internal exploit · alerting DSΣPDDCS [WEEKLY] Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internal install · alerting DSΣPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] Post-Auth Privilege Boundary Crossing on Edge/Management Appliances (low-priv -> admin within 10m) Internal exploit · alerting DSPDD [WEEKLY] Public-facing app auth/authz bypass into server-side code execution (patch-bypass wave) Internal exploit · alerting DSΣPDDCS [WEEKLY] Public-Facing App Auth-Bypass to Server-Side Code Execution (web-server process spawning a shell/interpreter) Internal exploit · alerting DSΣPDDCS [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] SSRF-Driven Secret Egress: Public-Facing App Reaches Cloud Metadata/Attacker Host Internal actions · alerting DSΣPDDCSCW [WEEKLY] Sub-admin grants Owner/Administrator role then grantee signs in from a different source within 60 minutes Internal exploit · alerting DSPDDCW [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD [WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) Internal install · alerting DSΣPDDCS [WEEKLY] Web-Server Process Post-Exploit Anchor: Plugin/Extension RCE Leading to Shell Spawn or Webroot Script Drop Internal install · alerting DSΣPDD [WEEKLY] Web-tier interpreter post-exploitation: shell/net-tool spawn, secret-file read, or cloud IMDS reach Internal install · alerting DSΣPDDCSCW Cisco IOS XE Request Platform Package Describe Shell Pattern ESCU actions · alerting P Cisco IOS XE WebUI Login From IOSd Local Port ESCU actions · alerting P Cisco IOS XE WebUI Programmatic Configuration ESCU actions · hunting P CrushFTP Server Side Template Injection ESCU actions · alerting P Ivanti VTM New Account Creation ESCU actions · alerting P Ollama Possible RCE via Model Loading ESCU actions · hunting P Ollama Suspicious Prompt Injection Jailbreak ESCU actions · hunting P PTC Windchill Gateway Command Execution ESCU actions · hunting P PTC Windchill GW READY OK Probe ESCU actions · hunting P Suspicious Java Classes ESCU actions · hunting P Cisco NVM - Webserver Download From File Sharing Website ESCU actions · alerting P ConnectWise ScreenConnect Path Traversal ESCU actions · alerting P ConnectWise ScreenConnect Path Traversal Windows SACL ESCU actions · alerting P Detect Exchange Web Shell ESCU actions · alerting P Exchange PowerShell Abuse via SSRF ESCU actions · alerting P Java Writing JSP File ESCU actions · alerting P Linux Suspicious Child Process of PostgreSQL ESCU actions · alerting P Linux Suspicious React or Next.js Child Process ESCU actions · alerting P Living Off The Land Detection ESCU actions · alerting P Log4Shell CVE-2021-44228 Exploitation ESCU actions · alerting P MOVEit Certificate Store Access Failure ESCU actions · hunting P MOVEit Empty Key Fingerprint Authentication Attempt ESCU actions · hunting P MS Exchange Mailbox Replication service writing Active Server Pages ESCU actions · alerting P Outbound Network Connection from Java Using Default Ports ESCU actions · alerting P PaperCut NG Suspicious Behavior Debug Log ESCU actions · hunting P Web or Application Server Spawning a Shell ESCU actions · alerting P Windows Identify PowerShell Web Access IIS Pool ESCU actions · hunting P Windows Metasploit Confluence Plugin Execution ESCU actions · alerting P Windows MOVEit Transfer Writing ASPX ESCU actions · alerting P Windows PaperCut NG Spawn Shell ESCU actions · alerting P Windows SharePoint Spinstall0 Webshell File Creation ESCU actions · alerting P Windows Shell or Script Execution From IIS Directory ESCU actions · hunting P Windows Shell Process from CrushFTP ESCU actions · alerting P Windows Suspicious React or Next.js Child Process ESCU actions · alerting P Windows TeamCity Payload Execution from Temp Directory ESCU actions · alerting P Windows TeamCity Plugin Installed ESCU actions · hunting P Windows Unusual File Creation in Confluence Directory ESCU actions · hunting P Windows WSUS Spawning Shell ESCU actions · alerting P WinRM Spawning a Process ESCU actions · alerting P Cisco SD-WAN - Arbitrary File Overwrite Exploitation Activity ESCU actions · alerting P Cisco SD-WAN - Low Frequency Rogue Peer ESCU actions · hunting P Cisco SD-WAN - Peering Activity ESCU actions · hunting P Cisco Secure Firewall - High Priority Intrusion Classification ESCU actions · alerting P Cisco Secure Firewall - Lumma Stealer Activity ESCU actions · alerting P Cisco Secure Firewall - Oracle E-Business Suite Correlation ESCU actions · alerting P Cisco Secure Firewall - Oracle E-Business Suite Exploitation ESCU actions · alerting P Cisco Secure Firewall - React Server Components RCE Attempt ESCU actions · alerting P Cisco Secure Firewall - Static Tundra Smart Install Abuse ESCU actions · alerting P Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity ESCU actions · alerting P Cisco Smart Install Oversized Packet Detection ESCU actions · alerting P Cisco Smart Install Port Discovery and Status ESCU actions · alerting P Detect Outbound LDAP Traffic ESCU actions · hunting P Detect Zerologon via Zeek ESCU actions · alerting P F5 BIG-IP iControl REST Vulnerability CVE-2022-1388 ESCU actions · alerting P Access to Vulnerable Ivanti Connect Secure Bookmark Endpoint ESCU actions · alerting P Adobe ColdFusion Access Control Bypass ESCU actions · hunting P Adobe ColdFusion Unauthenticated Arbitrary File Read ESCU actions · hunting P Cisco IOS XE Implant Access ESCU actions · alerting P Citrix ADC and Gateway CitrixBleed 2 Memory Disclosure ESCU actions · hunting P Citrix ADC and Gateway Unauthorized Data Disclosure ESCU actions · alerting P Citrix ADC Exploitation CVE-2023-3519 ESCU actions · hunting P Citrix ShareFile Exploitation CVE-2023-24489 ESCU actions · hunting P Confluence CVE-2023-22515 Trigger Vulnerability ESCU actions · alerting P Confluence Data Center and Server Privilege Escalation ESCU actions · alerting P Confluence Pre-Auth RCE via OGNL Injection CVE-2023-22527 ESCU actions · alerting P Confluence Unauthenticated Remote Code Execution CVE-2022-26134 ESCU actions · alerting P ConnectWise ScreenConnect Authentication Bypass ESCU actions · alerting P CrushFTP Authentication Bypass Exploitation ESCU actions · alerting P Detect F5 TMUI RCE CVE-2020-5902 ESCU actions · alerting P Exploit Public Facing Application via Apache Commons Text ESCU actions · hunting P Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 ESCU actions · alerting P Fortinet Appliance Auth bypass ESCU actions · alerting P HTTP Duplicated Header ESCU actions · hunting P HTTP Rapid POST with Mixed Status Codes ESCU actions · hunting P HTTP Request to Reserved Name on IIS Server ESCU actions · alerting P Hunting for Log4Shell ESCU actions · hunting P Ivanti Connect Secure Command Injection Attempts ESCU actions · alerting P Ivanti Connect Secure SSRF in SAML Component ESCU actions · alerting P Ivanti Connect Secure System Information Access via Auth Bypass ESCU actions · hunting P Ivanti EPM SQL Injection Remote Code Execution ESCU actions · alerting P Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078 ESCU actions · alerting P Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082 ESCU actions · alerting P Java Class File download by Java User Agent ESCU actions · alerting P Jenkins Arbitrary File Read CVE-2024-23897 ESCU actions · alerting P JetBrains TeamCity Authentication Bypass CVE-2024-27198 ESCU actions · alerting P JetBrains TeamCity Authentication Bypass Suricata CVE-2024-27198 ESCU actions · alerting P JetBrains TeamCity Limited Auth Bypass Suricata CVE-2024-27199 ESCU actions · alerting P JetBrains TeamCity RCE Attempt ESCU actions · alerting P Juniper Networks Remote Code Execution Exploit Detection ESCU actions · alerting P Log4Shell JNDI Payload Injection Attempt ESCU actions · hunting P Log4Shell JNDI Payload Injection with Outbound Connection ESCU actions · hunting P Nginx ConnectWise ScreenConnect Authentication Bypass ESCU actions · alerting P PaperCut NG Remote Web Access Attempt ESCU actions · alerting P ProxyShell ProxyNotShell Behavior Detected ESCU actions · alerting P SAP NetWeaver Visual Composer Exploitation Attempt ESCU actions · hunting P Spring4Shell Payload URL Request ESCU actions · alerting P SQL Injection with Long URLs ESCU actions · alerting P Tomcat Session Deserialization Attempt ESCU actions · hunting P Tomcat Session File Upload Attempt ESCU actions · hunting P VMWare Aria Operations Exploit Attempt ESCU actions · alerting P VMware Server Side Template Injection Hunt ESCU actions · hunting P VMware Workspace ONE Freemarker Server-side Template Injection ESCU actions · hunting P Web JSP Request via URL ESCU actions · alerting P Web Remote ShellServlet Access ESCU actions · alerting P Web Spring4Shell HTTP Request Class Module ESCU actions · alerting P Web Spring Cloud Function FunctionRouter ESCU actions · alerting P Windows Exchange Autodiscover SSRF Abuse ESCU actions · alerting P Windows IIS Server PSWA Console Access ESCU actions · hunting P Windows SharePoint Spinstall0 GET Request ESCU actions · alerting P Windows SharePoint ToolPane Endpoint Exploitation Attempt ESCU actions · alerting P WordPress Bricks Builder plugin RCE ESCU actions · alerting P WS FTP Remote Code Execution ESCU actions · alerting P Ivanti Sentry Authentication Bypass ESCU actions · alerting P Linux Java Spawning Shell ESCU actions · alerting P Splunk Enterprise Windows Deserialization File Partition ESCU actions · alerting P Splunk RCE via Serialized Session Payload ESCU actions · hunting P Splunk Unauthenticated Log Injection Web Service Log ESCU actions · hunting P Windows Java Spawning Shells ESCU actions · alerting P [LLM] Ray host OOB callback to oast.fun/interact.sh (ShadowRay exploit validation) Bespoke exploit · alerting DSΣPDDCSCW [LLM] MLflow unauthenticated webhook create + /test SSRF exploitation (CVE-2026-64849) Bespoke exploit · alerting SΣP [LLM] MLflow/Python server egress to cloud metadata IP 169.254.169.254 (SSRF landing) Bespoke exploit · hunting DSΣPDDCS [LLM] GitLab GraphQL mutation delivered over HTTP GET to /api/graphql (CVE-2026-19650) Bespoke exploit · hunting SΣP [LLM] Self-managed GitLab running versions vulnerable to CVE-2026-19478 / CVE-2026-19650 Bespoke recon · alerting DS [LLM] Node.js runtime spawning a shell/command interpreter (vm2 sandbox breakout RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Vulnerable vm2 package (<=3.11.5) exposed to CVE-2026-47698 sandbox breakout Bespoke exploit · hunting DS [LLM] New API CVE-2026-71479: integer-overflow multiplier in billing request (self-crediting) Bespoke exploit · alerting SΣPDD [LLM] conflibot command injection: shell spawned by Node action with git + shell metacharacters (CVE-2026-55158) Bespoke exploit · alerting DSΣPCS [LLM] Clop hex-named JSP webshell dropped under PTC Windchill /login (CVE-2026-12569) Bespoke install · alerting DSΣPDDCS [LLM] POST to hex-named JSP webshell under /Windchill/login/ in web/proxy logs Bespoke exploit · hunting SΣP [LLM] vCenter CVE-2026-59310 PoC cron drop + backdoor fetch (zz-poc59310-syslog.log) Bespoke exploit · hunting DSΣPDDCS [LLM] Rogue vSphere admin account creation via GoodMoodle-VCFleet UA from 146.59.252.178 Bespoke delivery · hunting DSΣPDDCS [LLM] SAP Commerce Cloud CVE-2026-58231: default OAuth client abuse against Data Hub Adapter Bespoke exploit · hunting SΣP [LLM] SAP Commerce (Hybris) Java process spawning OS command shell — CVE-2026-58231 RCE payoff Bespoke exploit · hunting DSΣPDDCS [LLM] Inbound Screen Sharing (VNC port 5900) from a public IP to a Mac — CVE-2026-65400 exposure Bespoke exploit · hunting DSΣPCS [LLM] Internet-facing macOS hosts unpatched against the Screen Sharing CVE cluster (exposure hunt) Bespoke recon · hunting DSP [LLM] SharePoint STS certificate/thumbprint disclosure endpoint accessed from external IP (CVE-2026-55040 recon) Bespoke recon · alerting SΣP [LLM] SharePoint CVE-2026-55040 chain: metadata recon then post-bypass API calls from one external IP Bespoke actions · alerting SP [LLM] ColdFusion server process spawning OS shell / LOLBin (CVE-2026-48362 / CVE-2026-48273 RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Exposure: unpatched Adobe ColdFusion / Campaign Classic (APSB26-90 & APSB26-120 CVEs) Bespoke exploit · hunting DSP [LLM] Traefik ReplacePathRegex auth bypass: glued dot-dot traversal in request path Bespoke exploit · alerting SΣPDD [LLM] Traefik path-traversal bypass CONFIRMED: traversal request returns 2xx on protected route Bespoke actions · alerting SPDD [LLM] Traefik dynamic config write introducing unbounded ReplacePathRegex capture group Bespoke weapon · hunting DSΣPCS [LLM] Vulnerable Traefik version exposed to CVE-2026-65600 / CVE-2026-48020 Bespoke recon · alerting DS [LLM] Nuxt/Vite dev server (node.exe) spawns shell or LOLBin child — DevTools RPC RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Nuxt dev server bound to non-loopback interface (nuxi/nuxt dev --host) Bespoke delivery · hunting DSΣPDDCS [LLM] Inbound non-loopback connection to Nuxt/Vite dev server (node.exe HMR port) Bespoke delivery · hunting DSPCS [LLM] Unauthenticated Flowise OAuth2 token-refresh endpoint access from external source (CVE-2026-70478) Bespoke exploit · alerting SΣP [LLM] Flowise OAuth2 credentialId enumeration (mixed 200/404 probing) Bespoke recon · alerting SP [LLM] Flowise CSV Agent prompt-injection: validator-bypass Python tokens POSTed to /api/v1/prediction Bespoke delivery · hunting SP [LLM] Flowise (node) process spawning a shell — CVE-2026-70477 pyodide→child_process RCE landing Bespoke exploit · alerting DSΣPCS [LLM] Malicious csvFile data URI with Python/JS breakout posted to Flowise /api/v1/prediction Bespoke exploit · hunting SΣP [LLM] Flowise Node.js process spawning OS shell/recon (Pyodide js-interop RCE sink) Bespoke actions · alerting DSΣPDDCS [LLM] Unicode homoglyph dunder payload to Flowise /api/v1/prediction (validator bypass) Bespoke delivery · hunting SP [LLM] Flowise additionalConfig database-path override in vector-upsert API request (CVE-2026-69259) Bespoke exploit · hunting SP [LLM] Flowise node process writes SQLite DB file to system directory (arbitrary-write RCE primitive) Bespoke install · alerting DSΣPCS [LLM] Flowise node runtime spawns shell interpreter (post-exploit command execution) Bespoke exploit · alerting DSΣPCS [LLM] Flowise node.js spawns Unix shell/command binaries as root (CSVAgent Pyodide RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Flowise CSVAgent exploit HTTP sequence: chatflow create + prediction trigger Bespoke exploit · hunting SP [LLM] Flowise/node process spawning Unix shell or netcat reverse shell (CVE-2026-69254 vm2 escape) Bespoke install · alerting DSΣPDDCS [LLM] Flowise API exploitation: path-traversal / JS-injection payloads to /api/v1 endpoints (CVE-2026-69254) Bespoke delivery · hunting SΣP [LLM] Flowise node process spawning shell/netcat (TypeORM DataSource RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Malicious JavaScript entity file written into Flowise storage by node Bespoke delivery · hunting DSΣPCS [LLM] Sequelize Oracle SQLi: TO_DATE/TO_TIMESTAMP quote-bypass payload in HTTP request Bespoke delivery · alerting SΣP [LLM] ApostropheCMS SSPP payload: $pullAll/__proto__ PATCH to piece-type API (CVE-2026-53609) Bespoke exploit · alerting SΣP [LLM] ApostropheCMS auth-bypass symptom: protected piece-type endpoint 401/403 → 200 transition Bespoke actions · hunting SP [LLM] ApostropheCMS exploit chain: unauth PATCH to /@apostrophecms/global → 200 GET on /user within 30s Bespoke exploit · alerting SP [LLM] NocoBase anonymous account sign-up via auth-basic (allowSignUp) exploitation prerequisite Bespoke delivery · hunting SΣP [LLM] CVE-2026-52887 SQLi payload in NocoBase myInAppChannels filter[latestMsgReceiveTimestamp][$lt] Bespoke exploit · alerting SΣP [LLM] PostgreSQL container process spawning shell — COPY TO PROGRAM RCE (CVE-2026-52887) Bespoke install · alerting DSΣPCS [LLM] NocoBase sign-up immediately followed by myInAppChannels exploitation from same source Bespoke delivery · alerting SP [LLM] Malicious vault-addr annotation on ConfigMap/Secret admission (CVE-2026-54725) Bespoke delivery · alerting SΣPDD [LLM] Vulnerable Pterodactyl Wings node (< v1.12.3) exposed to CVE-2026-52855 config-secret disclosure Bespoke exploit · hunting DSP [LLM] Rails web process reads /proc/self/environ or app secrets (Active Storage libvips file-read) Bespoke actions · hunting SPCS [LLM] Ruby/Puma Rails web process spawns a shell (post-file-read RCE via forged secret_key_base cookie) Bespoke exploit · alerting DSΣPCS [LLM] Internet-facing hosts running activestorage vulnerable to CVE-2026-66066 Bespoke exploit · hunting DS [LLM] Flyto2 flyto-verification unauthenticated POST /run on :8344 (CVE-2026-67426 SSRF entry) Bespoke exploit · hunting DSΣPCS [LLM] flyto-verification SSRF to cloud metadata IP (169.254.169.254) — runner-secret/IMDS theft Bespoke actions · hunting DSΣPDDCS [LLM] Langflow CVE-2026-33017 unauthenticated RCE exploitation (build_public_tmp) Bespoke exploit · hunting DSΣPDD [LLM] Logging-operator Flow/Output CRD injects Fluentd @type exec block (CVE-2026-54680) Bespoke delivery · alerting SΣPDD [LLM] Prebid-server SSRF payload in OpenRTB2 auction request parameters Bespoke exploit · hunting SΣP [LLM] Prebid-server outbound requests to internal ranges / internal host fan-out (SSRF) Bespoke actions · alerting DSPDDCSCW [LLM] Prebid-server SSRF filter-bypass via encoded internal host in request Bespoke exploit · hunting SΣP [LLM] @hypequery/clickhouse SQLi: backslash-quote / JSON-apostrophe payload at web edge (CVE-2026-54658) Bespoke exploit · hunting SΣP [LLM] Vulnerable @hypequery/clickhouse package (<2.5.1) present in node_modules Bespoke recon · hunting DSΣPCS [LLM] goshs launched with exploitable empty-credential SFTP config (CVE-2026-62325) Bespoke exploit · alerting DSΣPDDCS [LLM] goshs basic-auth flag with empty username or password (config-audit hunt) Bespoke exploit · hunting DSΣPDDCS [LLM] Unauthenticated inbound SFTP to goshs followed by remote file operations Bespoke actions · hunting DSPDDCS [LLM] Anomalous Host header on Poweradmin OIDC/SAML/logout endpoints (CVE-2026-54588) Bespoke exploit · hunting SP [LLM] Host header fuzzing burst against Poweradmin auth endpoints from single source Bespoke recon · alerting SP [LLM] Spike of AADSTS50011 redirect_uri mismatch at IdP (poisoned Poweradmin callback) Bespoke exploit · alerting DSPDD [LLM] Pheditor forced-password-change auth bypass — POST to pheditor.php Bespoke exploit · hunting SΣP [LLM] Web-server / PHP process writes new .php file under webroot (post-Pheditor webshell drop) Bespoke install · hunting DSΣPDDCS [LLM] Budibase REST query published to PUBLIC role (unauth cred-leak enabler) Bespoke exploit · hunting SΣP [LLM] Stacked SQL-injection payload against Budibase datasource query API (multipleStatements) Bespoke exploit · alerting SΣP [LLM] MySQL server (mysqld) writes exfil file via SELECT INTO OUTFILE on Budibase DB host Bespoke actions · hunting DSΣPCS [LLM] OpenAM /authservice CustomCallback ClassName XML — CVE-2026-62379 pre-auth Class.forName RCE Bespoke exploit · alerting SP [LLM] OpenAM/Tomcat java process spawning shell or LOLBin — CVE-2026-62379 post-exploitation Bespoke install · alerting DSΣPDDCS [LLM] OpenAM WebAuthn pre-auth Java deserialization payload to /json/authenticate (CVE-2026-62263) Bespoke exploit · alerting SΣP [LLM] OpenAM/Tomcat Java process spawning a shell — post-deserialization RCE (CVE-2026-62263) Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js host process spawning OS shell (Nunjucks SSTI child_process.execSync RCE) Bespoke exploit · hunting DSΣPDDCS [LLM] Vulnerable @prompty/core package present in node_modules (GHSA-w28w-gp39-m4p6 exposure) Bespoke delivery · hunting DSΣPDDCS [LLM] Velocity.js SSTI RCE payload (constructor.constructor→child_process) in HTTP request Bespoke delivery · alerting SΣP [LLM] Node.js process spawning shell / recon binary (velocityjs SSTI RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] Vulnerable seroval (<=1.5.2) / TanStack Start (<1.167.30) exposure to CVE-2026-59940 deserialization RCE Bespoke exploit · hunting DS [LLM] Auth.js fail-open exploited: protected routes served 200/302 during an active auth-error window Bespoke exploit · hunting SP [LLM] Unpatched Zimbra Collaboration exposed to CVE-2025-66376 (Void Blizzard target) Bespoke exploit · hunting DS [LLM] wp2shell SQLi via author__not_in REST parameter (CVE-2026-60137) Bespoke exploit · alerting SΣP [LLM] Gitea PR head-branch update via API v1 pulls/{index}/update (CVE-2026-58443 exploit vector) Bespoke exploit · hunting SΣP [LLM] Vulnerable Gitea instance exposed to CVE-2026-58443 (≤1.26.4) Bespoke exploit · hunting DSP [LLM] Client-supplied X-WEBAUTH-USER header reaching Gitea (CVE-2026-20896 impersonation) Bespoke exploit · hunting DSPCS [LLM] Gitea container started with reverse-proxy auth exposing permissive trusted-proxies (CVE-2026-20896) Bespoke install · hunting DSΣPDDCS [LLM] Gitea webhook/migration SSRF reaching cloud metadata endpoints (IMDS / Azure WireServer) Bespoke actions · hunting DSΣPDDCS [LLM] Gitea process egress to SSRF allow-list bypass internal ranges (CGNAT / 172.32.0.0/11) Bespoke recon · hunting DSΣPDDCS [LLM] Vulnerable Gitea version exposed to CVE-2026-22874 SSRF (pre-1.26.4) Bespoke weapon · hunting DS [LLM] Vitest Browser Mode / test API (node.exe) accepting inbound connections on 63315/51204 from non-loopback host Bespoke exploit · hunting DSΣPDDCS [LLM] LightRAG destructive document ops post-bypass (DELETE /documents, clear_cache, unauth upload) Bespoke actions · alerting SΣP [LLM] WordPress wp2shell batch REST API pre-auth RCE exploitation (CVE-2026-63030/60137) Bespoke exploit · alerting SΣP [LLM] Web server daemon (php-fpm/apache/nginx/w3wp) spawning a shell or network tool — wp2shell post-exploit code execution Bespoke exploit · alerting DSΣPDDCS [LLM] Siemens RUGGEDCOM ROX II devices exposed to CVE-2025-40947/48/49 (firmware < V2.17.1) Bespoke exploit · alerting DS [LLM] Pheditor terminal RCE: web-server/PHP process spawns shell (CVE-2026-55579) Bespoke exploit · alerting DSΣPDDCS [LLM] Pheditor file-upload abuse: web-server process writes new .php webshell Bespoke install · alerting DSΣPDDCS [LLM] Pheditor default-credential exploitation traffic: POST to /pheditor.php from external source Bespoke delivery · hunting SΣP [LLM] EnvoyExtensionPolicy Lua with double-slash path traversal to secrets (CVE-2026-53713) Bespoke exploit · alerting SΣPDD [LLM] EnvoyExtensionPolicy Lua invoking os/io/debug file primitives Bespoke exploit · hunting SΣPDD [LLM] Anomalous EnvoyExtensionPolicy submitter / suspicious policy name Bespoke delivery · hunting SΣPDD [LLM] Vulnerable Envoy Gateway version exposed to CVE-2026-53713 Bespoke recon · hunting DS [LLM] Unauthenticated access to MantisBT admin/install.php on a production host (CVE-2026-52847) Bespoke recon · hunting SΣP [LLM] Credential-phishing form injection via reflected XSS in MantisBT install.php (CVE-2026-52881) Bespoke delivery · alerting SΣP [LLM] Meta open-redirect injection via reflected XSS in MantisBT install.php (CVE-2026-52881) Bespoke delivery · alerting SΣP [LLM] Broad reflected HTML/XSS payload tokens in MantisBT install.php query string Bespoke exploit · hunting SΣP [LLM] MantisBT self-registration (signup.php) followed by SOAP replay to mantisconnect.php from same source Bespoke exploit · hunting SP [LLM] FacturaScripts upload endpoint: path-traversal sequence in multipart filename Bespoke exploit · alerting SΣP [LLM] FacturaScripts: PHP/.htaccess web-shell written into web-served Dinamic/Assets or node_modules Bespoke install · alerting DSΣPDDCS [LLM] FacturaScripts RCE chain: .htaccess handler-remap override plus payload drop in same asset dir Bespoke exploit · alerting DSPCS [LLM] n8n-MCP vulnerable multi-tenant config exposure (ENABLE_MULTI_TENANT without version-tool mitigation) Bespoke exploit · hunting SP [LLM] Anyquery server mode bound to all interfaces (exposed unauthenticated MySQL port) Bespoke delivery · hunting DSΣPDDCS [LLM] Inbound connection to Anyquery listener from a public IP Bespoke delivery · hunting DSPCS [LLM] Anyquery process writing files to cron/webroot/SSH persistence paths (ATTACH DATABASE AFW) Bespoke install · alerting DSΣPCS [LLM] ATTACH DATABASE statement targeting persistence paths in Anyquery query logs Bespoke exploit · hunting SPDD [LLM] FacturaScripts CVE-2026-45262 SQLi: parenthesis-bypass in REST API filter[] key Bespoke exploit · alerting SΣP [LLM] FacturaScripts filter[] SQLi column-count / schema enumeration (burst probing) Bespoke exploit · hunting SP [LLM] Kimai authenticated session activity with no preceding form-login POST (forged remember-me cookie) Bespoke exploit · hunting SP [LLM] Kimai forged Symfony login-link request (user+expires+hash signed URL) to super_admin Bespoke exploit · hunting SΣP [LLM] DIRAC FileCatalog checkDataset SQL injection carrying Python eval gadget (CVE-2026-61667) Bespoke exploit · hunting SPDD [LLM] DIRAC FileCatalog service Python process spawns shell or recon binary (eval RCE) Bespoke install · alerting DSΣPDDCS [LLM] DIRAC ReqManager service (CVE-2026-45579) spawning a shell or recon/egress binary Bespoke exploit · alerting DSΣP [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) Bespoke exploit · alerting DSΣPCS [LLM] FileBrowser reverse-proxy bypass: direct external access to exposed port 8085 Bespoke delivery · alerting DSΣPDDCS [LLM] FileBrowser instance configured with auth.method=proxy (exploitable-config exposure) Bespoke recon · hunting DSΣPDDCS [LLM] Authorizer /authorize implicit-flow token leak to off-origin redirect_uri (CVE-2026-54072) Bespoke exploit · alerting SΣP [LLM] Authorizer unauthenticated /graphql client_id reconnaissance (CVE-2026-54072 pre-exploit) Bespoke recon · hunting SΣP [LLM] Authorizer /authorize redirect_uri iteration — multiple distinct targets from one source Bespoke exploit · alerting SP [LLM] Spike in Authorizer /authorize 302 redirects to off-origin hosts (bulk token exfiltration) Bespoke actions · hunting SP [LLM] YesWiki Bazar CalcField eval() RCE — dangerous PHP functions in form-save request Bespoke exploit · alerting SΣP [LLM] YesWiki CalcField ReDoS/stack-overflow DoS — deeply nested parentheses payload Bespoke actions · alerting SΣP [LLM] YesWiki post-RCE — php-fpm/apache spawns Unix shell or recon binary (www-data) Bespoke install · alerting DSΣPDDCS [LLM] YesWiki CalcField exploit attempts — PHP parse/fatal errors from CalcField.php in syslog Bespoke exploit · hunting SPDD [LLM] YesWiki BazarImportAction object-injection exploit request (CVE-2026-52777) Bespoke exploit · alerting SΣP [LLM] Base64 PHP-serialized-object payload in importfiche POST body Bespoke exploit · alerting SP [LLM] YesWiki web-server process spawning an OS shell (deserialization RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] YesWiki unauthenticated erasespamedcomments page-deletion invocation (CVE-2026-52766) Bespoke exploit · alerting SΣP [LLM] Rocket.Chat Livechat file-upload ID enumeration sweep (ObjectId harvest) Bespoke actions · alerting SP [LLM] Rocket.Chat anonymous Livechat visitor bootstrap chained to file-upload access Bespoke exploit · alerting SP [LLM] Rocket.Chat file-upload request carrying Livechat auth params (IDOR signature) Bespoke exploit · hunting SΣP [LLM] phpBB CVE-2026-48611 auth bypass via login_link auth_provider=apache Bespoke exploit · alerting SΣP [LLM] phpBB CVE-2026-48611 post-exploit ACP access from exploiting IP Bespoke actions · alerting SP [LLM] HTTP Basic Authorization header sent to phpBB login_link endpoint Bespoke exploit · hunting SP [LLM] Exposed phpBB instances vulnerable to CVE-2026-48611 / 48612 / 29199 auth bypass Bespoke exploit · hunting DSP [LLM] phpBB ACP access from a source IP with no prior login (CVE-2026-48611 session hijack) Bespoke exploit · hunting SP [LLM] phpBB password-reset host-header poisoning (CVE-2026-29199) Bespoke exploit · hunting SP [LLM] phpBB OAuth account-binding CSRF via cross-site request to /user/oauth/authenticate/ (CVE-2026-48612) Bespoke exploit · hunting SP [LLM] Thymeleaf SpEL tab-character sandbox bypass payload in HTTP request (CVE-2026-40478) Bespoke exploit · alerting SΣPDD [LLM] Java/Tomcat process writes .jsp webshell file to disk (CVE-2026-40478 post-exploit drop) Bespoke install · alerting DSΣPDDCS [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Bespoke actions · alerting DSΣPDDCS [LLM] Qinglong CVE-2026-3965 auth bypass via /open/user/init credential reset Bespoke exploit · alerting DSΣPDDCS [LLM] Qinglong CVE-2026-4047 case-mismatch auth bypass via /aPi/system/command-run Bespoke exploit · alerting DSΣPDD [LLM] Mailcow Autodiscover endpoint receives unauthenticated XSS payload (GHSA-f9xf-vc72-rcgm) Bespoke delivery · alerting SPDD [LLM] Mailcow login with HTML/JS injected into X-Real-IP header (GHSA-jprq-w83q-q62h) Bespoke delivery · alerting SPDD [LLM] BodySnatcher (CVE-2025-12420) ServiceNow Virtual Agent bot/integration exploit Bespoke exploit · alerting SΣP [LLM] BodySnatcher (CVE-2025-12420) — Hardcoded 'servicenowexternalagent' Token Observed in HTTP Traffic Bespoke exploit · alerting DSΣPDDCS [LLM] ServiceNow Virtual Agent Invocation of Hidden AIA-Agent Invoker AutoChat Topic (CVE-2025-12420) Bespoke exploit · alerting DSPDDCS [LLM] Vulnerable react-server-dom-* package versions (CVE-2025-55182) in workload inventory Bespoke recon · hunting DSPDDCS [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server Bespoke exploit · alerting DSΣPDDCS [LLM] Anomalous POST to Next.js Server Action / RSC endpoint with 5xx error clustering Bespoke exploit · alerting DSPDDCS [LLM] Next.js CVE-2025-29927 middleware bypass via x-middleware-subrequest header Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Spark CVE-2022-33891 doAs command injection — shell spawned by Spark JVM running 'id -Gn' with metacharacters Bespoke exploit · alerting DSΣPDDCS [LLM] ImageMagick 'convert -resize' command injection via sh -c in Go web app Bespoke exploit · hunting DSΣPDDCS [LLM] Inbound UDP/631 (CUPS IPP discovery) from external network Bespoke delivery · hunting DSΣPDDCS [LLM] Linux assets with vulnerable CUPS packages and external exposure (CVE-2024-47175/76/77/076) Bespoke recon · hunting DSPDDCS [LLM] Log4Shell JNDI exploitation string in inbound HTTP requests (CVE-2021-44228) Bespoke exploit · alerting SΣP [LLM] Log4Shell outbound JNDI callback from Java process to LDAP/RMI (CVE-2021-44228) Bespoke c2 · alerting DSΣPDDCS [LLM] Spring4Shell classLoader payload in inbound HTTP request (CVE-2022-22965) Bespoke exploit · alerting SΣP [LLM] Spring4Shell JSP webshell drop by Tomcat/Java into webapps (CVE-2022-22965) Bespoke install · alerting DSΣPDDCS [LLM] Exposure: hosts running python-multipart ≤0.0.6 / FastAPI ≤0.109.0 vulnerable to CVE-2024-24762 ReDoS Bespoke exploit · hunting DSP [LLM] Vulnerable HTTP/2 server inventory: CONTINUATION flood CVE cluster (CVE-2024-27316 et al.) Bespoke recon · hunting DSP [LLM] HTTP/2 server crash-loop on internet-facing host (CONTINUATION flood DoS exploitation signal) Bespoke actions · alerting DSPDDCS [LLM] Web-app runtime egress to AWS IMDS endpoint (169.254.169.254) — SSRF credential theft Bespoke actions · hunting DSΣPDDCS [LLM] Boolean-tautology SQL injection against Node.js/Express search endpoint Bespoke exploit · hunting SΣP [LLM] Vulnerable Jinja2 < 3.1.3 inventory pivot for CVE-2024-22195 (xmlattr XSS) Bespoke recon · hunting DSP [LLM] Jinja2 xmlattr XSS exploitation attempt in HTTP request parameters (CVE-2024-22195) Bespoke exploit · alerting SΣP [LLM] Struts CVE-2023-50164 path-traversal upload — HTTP exploit attempt Bespoke exploit · alerting DSΣPDD [LLM] Tomcat/Java process writes .jsp/.jspx webshell into webapp directory Bespoke install · alerting DSΣPDDCS [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) Bespoke actions · alerting DSΣPDDCS [LLM] PHP web-server process initiating outbound TCP (fsockopen reverse shell to attacker) Bespoke c2 · alerting DSΣPCS [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) Bespoke exploit · alerting DSΣPDDCS [LLM] Browser extension folder write at vulnerable React DevTools 4.27.8 / Vue.js devtools 6.5.0 Bespoke exploit · hunting DSΣPDDCS [LLM] Curl invoked with SOCKS5-hostname resolution (CVE-2023-38545 exploit precondition) Bespoke exploit · hunting DSΣPDDCS [LLM] Vulnerable libcurl/curl version present on host (CVE-2023-38545) Bespoke recon · hunting DS [LLM] Hosts exposed to libwebp heap overflow CVE-2023-4863 / CVE-2023-5129 (TVM) Bespoke weapon · alerting DSP [LLM] Vulnerable SnakeYAML <2.0 present (CVE-2022-1471 unsafe deserialization) Bespoke exploit · hunting DSP [LLM] JVM (java/javaw) spawning OS command interpreter — SnakeYAML gadget RCE outcome Bespoke exploit · hunting DSΣPDDCS [LLM] JVM outbound fetch of remote class/JAR to public host — URLClassLoader gadget Bespoke delivery · hunting DSPDDCS [LLM] node-serialize / serialize-to-js deserialization RCE payload marker `_$$ND_FUNC$$_` in web request Bespoke exploit · alerting SP [LLM] Node.js process spawning a command interpreter (deserialization RCE child_process exec) Bespoke exploit · alerting DSΣPDDCS [LLM] Ruby/Rails app server spawning a Unix shell (post-deserialization RCE) Bespoke exploit · alerting DSΣPCS [LLM] Exposure hunt: hosts running Spring Security vulnerable to CVE-2022-31692 forward/include auth bypass Bespoke recon · hunting DSP [LLM] SnakeYAML deserialization gadget tags in HTTP request (CVE-2022-1471) Bespoke exploit · alerting SΣP [LLM] Java process (java.exe/javaw.exe) spawning OS command shell — SnakeYAML RCE Bespoke exploit · hunting DSΣPDDCS [LLM] Java process outbound LDAP/RMI to fetch remote class — SnakeYAML JNDI gadget Bespoke c2 · alerting DSΣPDDCS [LLM] Pistache CVE-2022-26068 path traversal reading /etc/passwd via /doc/../ Bespoke exploit · alerting SΣP [LLM] Pistache binary theft via /doc/../../proc/self/exe path traversal Bespoke actions · alerting SΣP [LLM] curl --path-as-is traversal command exfiltrating /proc/self/exe or /etc/passwd Bespoke exploit · alerting DSΣPDDCS [LLM] URL-encoded directory traversal (%2e%2e) against node 'st' static-file route (CVE-2014-3744) Bespoke exploit · hunting SΣP [LLM] Vulnerable OpenSSL 3.0.0–3.0.6 exposure (CVE-2022-3602 / CVE-2022-3786, 'SpookySSL') Bespoke exploit · hunting DSP [LLM] Text4Shell (CVE-2022-42889) Commons Text interpolation payloads in inbound web requests Bespoke exploit · alerting SΣP [LLM] Java/JVM spawning OS shell after Text4Shell (CVE-2022-42889) script-engine RCE Bespoke install · alerting DSΣPDDCS [LLM] Git argument injection via --upload-pack option spawned by web-app runtime Bespoke exploit · alerting DSΣPDDCS [LLM] Mercurial argument injection via --config alias/hooks or --debugger from app runtime Bespoke exploit · alerting DSΣPDDCS [LLM] git/hg spawning a shell as child of a web-app runtime (argument-injection RCE evidence) Bespoke exploit · hunting DSPDDCS [LLM] Server application runtime spawning shell with /dev/tcp redirection (RCE to reverse shell) Bespoke exploit · alerting DSΣPCS [LLM] Apache Commons Configuration interpolation RCE payload in HTTP requests (CVE-2022-33980) Bespoke exploit · hunting SΣP [LLM] Java (ProcessBuilder) spawning shell/LOLBin child — Commons Config interpolation RCE Bespoke install · alerting DSΣPDDCS [LLM] Java process fetching first-seen external URL/DNS — Commons Config url/dns lookup (CVE-2022-33980) Bespoke c2 · hunting DSPDDCS [LLM] Prototype pollution attempt via __proto__ in URL query string (CVE-2021-23682, litespeed.js/appwrite) Bespoke exploit · hunting SΣP [LLM] Node.js web process overwriting application .js service file (GraphQL path-traversal file write) Bespoke exploit · hunting DSΣPCS [LLM] Spring4Shell classLoader property injection via dirContext.docBase (Glassfish/Payara/Tomcat) Bespoke exploit · alerting SΣP [LLM] Web path-traversal arbitrary file read via '../' in static-file URL (Crow CVE-2021-23514) Bespoke exploit · alerting SΣP [LLM] Arbitrary file write via '../' in upload 'name' parameter (Mongoose CVE-2022-25299) Bespoke install · alerting DSΣPCS [LLM] Spring4Shell (CVE-2022-22965) classLoader pipeline injection / JSP webshell call in web logs Bespoke exploit · alerting SΣP [LLM] Tomcat/Java JVM spawning command shell (Spring4Shell webshell command execution) Bespoke actions · hunting DSΣPDDCS [LLM] Spring4Shell (CVE-2022-22965) exploit: class.module.classLoader ClassLoader manipulation in HTTP request Bespoke exploit · alerting SΣP [LLM] Tomcat/Java writes JSP webshell into webapps (Spring4Shell post-exploit drop) Bespoke install · alerting DSΣPDDCS [LLM] Java/Tomcat spawns command shell or download tool (Spring4Shell RCE execution) Bespoke exploit · alerting DSΣPDDCS [LLM] Outbound connection to Spring4Shell Mirai staging IPs (107.174.133.167 / 194.31.98.186) Bespoke c2 · hunting DSΣPDDCSCW [LLM] HTTP request to executable PHP inside dompdf font cache (CVE-2022-28368 RCE trigger) Bespoke exploit · alerting SΣP [LLM] Magento CVE-2022-24086/24087 TrojanOrders checkout exploitation from known attacker IP Bespoke exploit · alerting SΣP [LLM] Magento webshell drop (health_check.php / pub-media PHP) written by web-server process Bespoke install · alerting DSΣPCS [LLM] Magento php-fpm/web-server spawning shell or download utility (CVE-2022-24086 RCE) Bespoke exploit · hunting DSΣPCS [LLM] Outbound or inbound connection to TrojanOrders C2/source IP 45.134.20.11 Bespoke c2 · hunting DSΣPDDCS [LLM] Magento CVE-2022-24086 template-directive injection in web requests (getTemplateFilter RCE) Bespoke exploit · hunting SΣP [LLM] Magento web process (w3wp/php-fpm/php-cgi) spawning OS shell — CVE-2022-24086 RCE Bespoke exploit · alerting DSΣPDDCS [LLM] Network activity involving CVE-2022-24086 attacker IP 45.134.20.11 Bespoke c2 · hunting DSΣPDDCSCW [LLM] Celery worker (Python) spawning a shell — CVE-2021-23727 stored command injection Bespoke exploit · hunting DSΣPCS [LLM] Hosts running Celery < 5.2.2 vulnerable to CVE-2021-23727 Bespoke recon · hunting DS [LLM] Log4Shell JNDI lookup string in inbound web request (CVE-2021-44228 exploitation) Bespoke exploit · alerting SP [LLM] Java/Tomcat application server spawning command shell or netcat (Log4Shell RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Java process making outbound LDAP/RMI callout to public host (JNDI egress) Bespoke c2 · hunting DSΣPDDCS [LLM] Log4j logging configuration file modified (CVE-2021-44832 JDBC Appender precondition) Bespoke weapon · hunting DSΣPDDCS [LLM] Java process outbound LDAP/RMI egress (CVE-2021-44832 remote JNDI data source load) Bespoke exploit · alerting DSΣPDDCS [LLM] Vulnerable Apache Log4j inventory exposed to CVE-2021-44832 (pre-2.17.1/2.12.4/2.3.2) Bespoke recon · hunting DSP [LLM] Log4j CVE-2021-45046 JNDI localhost-bypass payload (${jndi:...127.0.0.1#...}) in web requests Bespoke exploit · alerting DSΣPCS [LLM] Log4Shell RCE execution: java/javaw spawning a shell or LOLBin Bespoke exploit · alerting DSΣPDDCS [LLM] Log4Shell JNDI class fetch: java process outbound to LDAP/RMI ports Bespoke c2 · alerting DSΣPDDCS [LLM] Exposure: hosts running Log4j versions vulnerable to CVE-2021-45046 Bespoke recon · hunting DSP [LLM] Log4Shell JNDI lookup injection string in HTTP requests / process cmdline (${jndi:ldap}) Bespoke exploit · alerting DSΣPDDCS [LLM] Java process making outbound LDAP/RMI connection (Log4Shell second-stage class fetch) Bespoke delivery · hunting DSΣPDDCS [LLM] Java/Tomcat process spawning OS shell (Log4Shell Runtime.exec post-exploitation) Bespoke install · alerting DSΣPDDCS [LLM] Log4Shell JNDI lookup string in inbound HTTP request (URI / User-Agent / headers) Bespoke exploit · alerting SΣP [LLM] Java (java.exe/javaw.exe) spawning shell or LOLBin — Log4Shell post-exploitation Bespoke install · alerting DSΣPDDCS [LLM] Java process outbound to LDAP/RMI/DNS callback port — Log4Shell JNDI fetch Bespoke c2 · alerting DSΣPDDCS [LLM] Log4Shell JNDI lookup string in inbound web request (CVE-2021-44228 exploitation) Bespoke exploit · alerting SΣP [LLM] Java process outbound LDAP/RMI to public IP (Log4Shell JNDI callback) Bespoke c2 · hunting DSΣPDDCS [LLM] Java/Tomcat process spawning shell, curl or wget (Log4Shell RCE follow-on) Bespoke install · alerting DSΣPDDCS [LLM] Prototype pollution / type-confusion payload in web request (__proto__, constructor[prototype]) Bespoke exploit · hunting SΣP [LLM] CVE-2020-9484 Tomcat session deserialization: JSESSIONID path-traversal in HTTP request Bespoke exploit · alerting SΣP [LLM] Tomcat/Java server process spawning an OS command shell (CVE-2020-9484 RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] Attacker-staged .session deserialization payload written outside Tomcat's session store Bespoke delivery · hunting DSΣPDDCS [LLM] SuiteCRM PHAR deserialization via case-mixed phar:// wrapper in admin request Bespoke exploit · alerting SΣP [LLM] Direct HTTP 200 to SuiteCRM /upload or /files (post-.htaccess-deletion code exec) Bespoke actions · hunting SΣP [LLM] ImageMagick convert spawning shell/LOLBin child (ImageTragick CVE-2016-3714 RCE) Bespoke exploit · alerting DSΣPCS [LLM] Semicolon GET parameter cloaking in web/proxy logs (cache poisoning, CVE-2021-23336 / CVE-2020-28473) Bespoke exploit · hunting SΣP [LLM] Assets exposed to cache-poisoning CVEs (Python parse_qsl CVE-2021-23336 / Bottle CVE-2020-28473) Bespoke recon · hunting DSP [LLM] systeminformation inetChecksite curl argument injection (CVE-2020-7752) Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js (Express) process spawning a command shell — express-fileupload prototype-pollution RCE outcome Bespoke exploit · hunting DSΣPDDCS [LLM] Prototype-pollution payload (__proto__ / constructor.prototype) in inbound web requests to Express app Bespoke exploit · hunting SΣP [LLM] Exposure: hosts running express-fileupload vulnerable to CVE-2020-7699 Bespoke exploit · hunting DSP [LLM] Celery task injected into Apache Airflow message broker (unacked queue / execute_command) Bespoke delivery · alerting DSΣPDDCS [LLM] Apache Airflow Celery worker spawns non-airflow child (command-injection RCE, CVE-2020-11981) Bespoke exploit · alerting DSΣPCS [LLM] Apache Airflow task run with --pickle flag (pickle deserialization, CVE-2020-11982) Bespoke exploit · hunting DSΣPDDCS [LLM] Hosts exposed to Apache Airflow Celery broker RCE (CVE-2020-11981 / CVE-2020-11982) Bespoke recon · hunting DSP [LLM] GET request carrying a body / Content-Length — HTTP request smuggling (CL:CL) precursor Bespoke exploit · hunting SP [LLM] Front-end/back-end stack exposed to request-smuggling CVEs (nginx CVE-2020-12440, Werkzeug CVE-2019-16786) Bespoke exploit · alerting DSP [LLM] Ghostcat: inbound AJP (TCP/8009) connections from untrusted/public sources to Tomcat Bespoke exploit · hunting DSΣPDDCS [LLM] Ghostcat RCE: Tomcat/java process spawning a command shell (JSP webshell execution) Bespoke exploit · hunting DSΣPDDCS [LLM] Ghostcat exposure: assets running Tomcat versions vulnerable to CVE-2020-1938 Bespoke exploit · hunting DSP [LLM] Access to exposed Elector '/get-admin-users' credential-leaking API endpoint Bespoke exploit · alerting SΣP [LLM] Node.js launched with --insecure-http-parser flag (strict HTTP parsing disabled) Bespoke exploit · alerting DSΣPDDCS [LLM] Hosts exposed to Node.js Feb-2020 HTTP/TLS CVEs (CVE-2019-15604/15605/15606) Bespoke recon · hunting DS [LLM] Sequelize ORM JSON-path SQLi exploitation via ')) AS DECIMAL)' cast-break (CVE-2019-10748) Bespoke exploit · alerting SΣP [LLM] Exposure: jackson-databind <=2.9.9.2 / Spring Boot 2.1.7 vulnerable to CVE-2019-14379/14439 deserialization RCE Bespoke exploit · alerting DSP [LLM] Java/Spring Boot process spawning a shell — possible jackson-databind deserialization RCE Bespoke exploit · hunting DSΣPDDCS [LLM] Webmin password_change.cgi unauthenticated command injection exploit attempt (CVE-2019-15107) Bespoke exploit · hunting SΣP [LLM] Webmin RCE: miniserv/password_change.cgi spawning reverse shell (CVE-2019-15107) Bespoke exploit · alerting DSΣPDDCS [LLM] Vulnerable lodash (CVE-2019-10744 prototype pollution) present in software inventory Bespoke weapon · alerting DSP [LLM] Prototype pollution payload (__proto__ / constructor.prototype) in inbound web requests Bespoke exploit · hunting SΣP [LLM] Vulnerable urllib3 (<= 1.24.2 / CVE-2019-11236) present in software inventory Bespoke weapon · hunting DS [LLM] CRLF / HTTP-header injection in URL query string (urllib3 CVE-2019-11236 PoC shape) Bespoke exploit · hunting SΣP [LLM] jQuery prototype pollution payload (__proto__) in inbound HTTP request (CVE-2019-11358) Bespoke exploit · hunting SΣP [LLM] URL-encoded directory traversal (%2e%2e) against Node 'st' static file server Bespoke exploit · hunting SΣP [LLM] Successful sensitive-file disclosure via st traversal (/etc/passwd, package-lock.json) Bespoke actions · alerting SΣP [LLM] Anonymous access to Kubernetes aggregated API (CVE-2018-1002105 exploit surface) Bespoke exploit · hunting SΣPDDCW [LLM] Zip Slip arbitrary file overwrite by archive-handling runtime (java/python) via path traversal Bespoke exploit · hunting DSΣPDDCS [LLM] Exposure: hosts running Zip Slip-vulnerable Apache Storm / Hadoop (CVE-2018-8008 / CVE-2018-8009) Bespoke exploit · alerting DSP [LLM] Apache Struts web app (java/Tomcat) spawning OS shell or recon — post-exploit RCE (CVE-2017-5638 / CVE-2017-9805) Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Struts OGNL / XStream exploit payload in WAF & web logs (CVE-2017-5638 + CVE-2017-9805) Bespoke exploit · alerting SP [LLM] Dust.js qs type-manipulation RCE payload in web request query string Bespoke exploit · alerting SΣP [LLM] qs prototype-override bypass exploit attempt in HTTP query string (CVE-2017-1000048) Bespoke exploit · alerting SΣP [LLM] ImageMagick binary spawning shell/recon process (ImageTragick CVE-2016-3714 delegate RCE) Bespoke exploit · hunting DSΣPCS [LLM] ImageMagick binary making outbound network connection (ImageTragick URL/HTTPS coder SSRF) Bespoke c2 · hunting DSPCS

Articles citing this technique (2574)