SolarWinds Serv-U CVE-2026-28318 Content-Encoding Abuse and Cl0p Post-Exploitatio
Detection rule monitoring for indicators of compromise related to SolarWinds Serv-U, including anomalous Content-Encoding headers, unexpected child process execution, large file staging indicative of data exfiltration (Cl0p-style), outbound exfiltration, SQL injection artifacts, and unauthorized LDAP/Active Directory object enumeration by the Serv-U process.
Microsoft Sentinel (KQL)

