Dahua p2pwn Backdoor Account Creation via CVE-2024-39943
This rule detects suspicious activity related to specific hardcoded indicators 'p2pwn', 'p2password', and references to 'cve-2024-39943'. It scans authentication logs (Identity) and EDR logs (process command lines) for these terms, flagging potential unauthorized access, credential use, or exploitation attempts associated with this specific threat activity.
Splunk (SPL)

