CVE-2025-53521 Unauthenticated RCE Attempt Against F5 BIG-IP APM

Detects possible unauthenticated exploitation attempts against CVE-2025-53521 (F5 BIG-IP APM RCE). Tightened from a generic 'any POST without a cookie on 443/8443' match (extremely broad, alerts on ordinary cookie-less API/health-check traffic) to POST requests specifically targeting F5 APM access-policy processing endpoints (/my.policy, /vdesk/) that lack a session cookie, since the CVE requires an access policy configured on the virtual server and legitimate APM sessions carry a session cookie. Added detection_filter (3 hits/60s per source) to suppress single incidental matches and prioritize repeated attempts. Note: public reporting for this CVE does not include the exact exploit URI/payload, so this is a behavioral/namespace heuristic, not a payload-specific signature — validate against your own APM traffic baseline and update once exploit specifics are published.