Robuta

Sponsor of the Day: Jerkmate
https://detection.fyi/sigmahq/sigma/emerging-threats/2021/exploits/cve-2021-26857/proc_creation_win_exploit_cve_2021_26857_msexchange/ Potential CVE-2021-26857 Exploitation Attempt | Detection.FYI Detects possible successful exploitation for vulnerability described in CVE-2021-26857 by looking for | abnormal subprocesses spawning by Exchange Server's … attempt detection fyipotential cve2021exploitation https://detection.fyi/sigmahq/sigma/emerging-threats/2021/exploits/cve-2021-21978/web_cve_2021_21978_vmware_view_planner_exploit/ CVE-2021-21978 Exploitation Attempt | Detection.FYI Detects the exploitation of the VMware View Planner vulnerability described in CVE-2021-21978 attempt detection fyicve 2021exploitation https://www.cybersecuritydive.com/news/tp-link-routers-exploitation-high-severity-flaw/817831/ TP-Link routers face exploitation attempt linked to high-severity flaw | Cybersecurity Dive Researchers warn a potential botnet is targeting a vulnerability in end-of-life devices. exploitation attempthigh severitycybersecurity divetprouters https://detection.fyi/sigmahq/sigma/emerging-threats/2022/exploits/cve-2022-21587/web_cve_2022_21587_oracle_ebs/ Potential CVE-2022-21587 Exploitation Attempt | Detection.FYI Detects potential exploitation attempts of CVE-2022-21587 an arbitrary file upload vulnerability impacting Oracle E-Business Suite (EBS). CVE-2022-21587 can … attempt detection fyipotential cve2022exploitation https://detection.fyi/loginsoft-research/detection-rules/threat-detection/nginx/cve-2013-2028/ CVE-2013-2028 Exploitation Attempt | Detection.FYI Detecting CVE-2013-2028 based on the error log generated on exploiting attempt detection fyicve 20132028exploitation https://detection.fyi/loginsoft-research/detection-rules/active-exploits/cve-2020-8515/ CVE-2020-8515 Exploitation Attempt | Detection.FYI Detection of pre-auth RCE attack in DrayTek Vigor series observed from our Honeypots attempt detection fyicve 20208515exploitation https://detection.fyi/sigmahq/sigma/emerging-threats/2021/exploits/cve-2021-26084/proc_creation_win_exploit_cve_2021_26084_atlassian_confluence/ Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt | Detection.FYI Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084 attempt detection fyiatlassian confluencecve 2021potentialexploitation https://detection.fyi/sigmahq/sigma/emerging-threats/2023/exploits/cve-2023-38831/file_event_win_exploit_cve_2023_38331_winrar_susp_double_ext/ CVE-2023-38331 Exploitation Attempt - Suspicious Double Extension File | Detection.FYI Detects the creation of a file with a double extension and a space by WinRAR. This could be a sign of exploitation of CVE-2023-38331 cve 2023exploitation attemptdetection fyisuspiciousdouble https://detection.fyi/sigmahq/sigma/emerging-threats/2023/exploits/cve-2023-34362-moveit-transfer-exploit/web_cve_2023_34362_known_payload_request.yml/ MOVEit CVE-2023-34362 Exploitation Attempt - Potential Web Shell Request | Detection.FYI Detects get requests to specific files used during the exploitation of MOVEit CVE-2023-34362 cve 2023exploitation attemptweb shelldetection fyimoveit https://detection.fyi/sigmahq/sigma/emerging-threats/2023/exploits/cve-2023-1389/proxy_exploit_cve_2023_1389_unauth_command_injection_tplink_archer_ax21/ CVE-2023-1389 Potential Exploitation Attempt - Unauthenticated Command Injection In TP-Link Archer... Detects potential exploitation attempt of CVE-2023-1389 an Unauthenticated Command Injection in TP-Link Archer AX21. cve 2023exploitation attemptcommand injection1389potential