Sponsor of the Day:
Jerkmate
https://detection.fyi/sigmahq/sigma/emerging-threats/2021/exploits/cve-2021-26857/proc_creation_win_exploit_cve_2021_26857_msexchange/
Potential CVE-2021-26857 Exploitation Attempt | Detection.FYI
Detects possible successful exploitation for vulnerability described in CVE-2021-26857 by looking for | abnormal subprocesses spawning by Exchange Server's …
attempt detection fyipotential cve2021exploitation
https://detection.fyi/sigmahq/sigma/emerging-threats/2021/exploits/cve-2021-21978/web_cve_2021_21978_vmware_view_planner_exploit/
CVE-2021-21978 Exploitation Attempt | Detection.FYI
Detects the exploitation of the VMware View Planner vulnerability described in CVE-2021-21978
attempt detection fyicve 2021exploitation
https://www.cybersecuritydive.com/news/tp-link-routers-exploitation-high-severity-flaw/817831/
TP-Link routers face exploitation attempt linked to high-severity flaw | Cybersecurity Dive
Researchers warn a potential botnet is targeting a vulnerability in end-of-life devices.
exploitation attempthigh severitycybersecurity divetprouters
https://detection.fyi/sigmahq/sigma/emerging-threats/2022/exploits/cve-2022-21587/web_cve_2022_21587_oracle_ebs/
Potential CVE-2022-21587 Exploitation Attempt | Detection.FYI
Detects potential exploitation attempts of CVE-2022-21587 an arbitrary file upload vulnerability impacting Oracle E-Business Suite (EBS). CVE-2022-21587 can …
attempt detection fyipotential cve2022exploitation
https://detection.fyi/loginsoft-research/detection-rules/threat-detection/nginx/cve-2013-2028/
CVE-2013-2028 Exploitation Attempt | Detection.FYI
Detecting CVE-2013-2028 based on the error log generated on exploiting
attempt detection fyicve 20132028exploitation
https://detection.fyi/loginsoft-research/detection-rules/active-exploits/cve-2020-8515/
CVE-2020-8515 Exploitation Attempt | Detection.FYI
Detection of pre-auth RCE attack in DrayTek Vigor series observed from our Honeypots
attempt detection fyicve 20208515exploitation
https://detection.fyi/sigmahq/sigma/emerging-threats/2021/exploits/cve-2021-26084/proc_creation_win_exploit_cve_2021_26084_atlassian_confluence/
Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt | Detection.FYI
Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084
attempt detection fyiatlassian confluencecve 2021potentialexploitation
https://detection.fyi/sigmahq/sigma/emerging-threats/2023/exploits/cve-2023-38831/file_event_win_exploit_cve_2023_38331_winrar_susp_double_ext/
CVE-2023-38331 Exploitation Attempt - Suspicious Double Extension File | Detection.FYI
Detects the creation of a file with a double extension and a space by WinRAR. This could be a sign of exploitation of CVE-2023-38331
cve 2023exploitation attemptdetection fyisuspiciousdouble
https://detection.fyi/sigmahq/sigma/emerging-threats/2023/exploits/cve-2023-34362-moveit-transfer-exploit/web_cve_2023_34362_known_payload_request.yml/
MOVEit CVE-2023-34362 Exploitation Attempt - Potential Web Shell Request | Detection.FYI
Detects get requests to specific files used during the exploitation of MOVEit CVE-2023-34362
cve 2023exploitation attemptweb shelldetection fyimoveit
https://detection.fyi/sigmahq/sigma/emerging-threats/2023/exploits/cve-2023-1389/proxy_exploit_cve_2023_1389_unauth_command_injection_tplink_archer_ax21/
CVE-2023-1389 Potential Exploitation Attempt - Unauthenticated Command Injection In TP-Link Archer...
Detects potential exploitation attempt of CVE-2023-1389 an Unauthenticated Command Injection in TP-Link Archer AX21.
cve 2023exploitation attemptcommand injection1389potential