• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Recon shell commands spawned via Artifactory plugin execution endpoint

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 27 days ago•0•0•0

    Detects reconnaissance commands (e.g., file listing, directory enumeration) executed as child processes of the JFrog Artifactory service. This behavior is often associated with the exploitation of Artifactory plugins or misconfigured endpoints that allow arbitrary code execution, enabling an attacker to perform discovery actions.

    Microsoft Sentinel (KQL)

    Tags

    T1083 - File and Directory DiscoveryT1505 - Server Software ComponentT1059 - Command and Scripting InterpreterTA0007 - DiscoveryTA0003 - PersistenceTA0002 - ExecutionProcess CreationCommand ExecutionWindowsLinuxArtifactorykql

    Found in

    • JFrog Artifactory Vulnerability Chain Enables Admin ControlLast updated 24 days ago
    • JFrog Artifactory Vulnerability Chain Enables Admin ControlLast updated 27 days ago
    • JFrog Artifactory Vulnerability Chain Enables Admin ControlLast updated 27 days ago
    • JFrog Artifactory Vulnerability Chain Enables Admin ControlLast updated 27 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?