Unauthenticated request to Splunk management REST API (CVE-2026-20253)
This rule detects potential exploitation attempts targeting the Splunk REST API (CVE-2026-20253) by monitoring for unauthenticated inbound requests to the /services/ path. It specifically looks for requests that lack the required Authorization or Cookie headers.
Suricata

