Web

Name Technique Datamodel
Adobe ColdFusion Access Control Bypass Exploit Public-Facing Application Web
Adobe ColdFusion Unauthenticated Arbitrary File Read Exploit Public-Facing Application Web
Citrix ADC Exploitation CVE-2023-3519 Exploit Public-Facing Application Web
Citrix ShareFile Exploitation CVE-2023-24489 Exploit Public-Facing Application Web
Confluence Unauthenticated Remote Code Execution CVE-2022-26134 Server Software Component, Exploit Public-Facing Application, External Remote Services Web
Detect F5 TMUI RCE CVE-2020-5902 Exploit Public-Facing Application None
Detect attackers scanning for vulnerable JBoss servers System Information Discovery, External Remote Services Web
Detect malicious requests to exploit JBoss servers None Web
Exploit Public Facing Application via Apache Commons Text Web Shell, Server Software Component, Exploit Public-Facing Application, External Remote Services Web
Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 Exploit Public-Facing Application, External Remote Services Web
Fortinet Appliance Auth bypass Exploit Public-Facing Application, External Remote Services Web
Hunting for Log4Shell Exploit Public-Facing Application, External Remote Services Web
Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078 Exploit Public-Facing Application, External Remote Services Web
Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082 Exploit Public-Facing Application, External Remote Services Web
Ivanti Sentry Authentication Bypass Exploit Public-Facing Application Web
Juniper Networks Remote Code Execution Exploit Detection Exploit Public-Facing Application, Ingress Tool Transfer, Command and Scripting Interpreter Web
Log4Shell JNDI Payload Injection Attempt Exploit Public-Facing Application, External Remote Services Web
Log4Shell JNDI Payload Injection with Outbound Connection Exploit Public-Facing Application, External Remote Services Network_Traffic, Web
Monitor Web Traffic For Brand Abuse None Web
PaperCut NG Remote Web Access Attempt Exploit Public-Facing Application, External Remote Services Web
ProxyShell ProxyNotShell Behavior Detected Exploit Public-Facing Application, External Remote Services Risk
SQL Injection with Long URLs Exploit Public-Facing Application Web
Spring4Shell Payload URL Request Web Shell, Server Software Component, Exploit Public-Facing Application, External Remote Services Web
Supernova Webshell Web Shell, External Remote Services Web
VMWare Aria Operations Exploit Attempt External Remote Services, Exploit Public-Facing Application, Exploitation of Remote Services, Exploitation for Privilege Escalation Web
VMware Server Side Template Injection Hunt Exploit Public-Facing Application, External Remote Services Web
VMware Workspace ONE Freemarker Server-side Template Injection Exploit Public-Facing Application, External Remote Services Web
Web JSP Request via URL Web Shell, Server Software Component, Exploit Public-Facing Application, External Remote Services Web
Web Spring Cloud Function FunctionRouter Exploit Public-Facing Application, External Remote Services Web
Web Spring4Shell HTTP Request Class Module Exploit Public-Facing Application, External Remote Services None
Windows Exchange Autodiscover SSRF Abuse Exploit Public-Facing Application, External Remote Services Web

Endpoint

CMD Echo Pipe - Escalation

Command and Scripting Interpreter, Windows Command Shell, Windows Service, Create or Modify System Process

Windows Post Exploitation Risk Behavior

Query Registry, System Network Connections Discovery, Permission Groups Discovery, System Network Configuration Discovery, OS Credential Dumping, System Info...

Disable Show Hidden Files

Hidden Files and Directories, Disable or Modify Tools, Hide Artifacts, Impair Defenses, Modify Registry

Living Off The Land

Ingress Tool Transfer, Exploit Public-Facing Application, Command and Scripting Interpreter, External Remote Services

Detect SharpHound Usage

Domain Account, Local Groups, Domain Trust Discovery, Local Account, Account Discovery, Domain Groups, Permission Groups Discovery

Back to Top ↑

Cloud

Back to Top ↑

Deprecated

Back to Top ↑

Application

Back to Top ↑

Network

Detect ARP Poisoning

Hardware Additions, Network Denial of Service, Adversary-in-the-Middle, ARP Cache Poisoning

Back to Top ↑

Web

Web JSP Request via URL

Web Shell, Server Software Component, Exploit Public-Facing Application, External Remote Services

Back to Top ↑