Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
2
Contributors
2
Categories
1
1
1
1
1
Platforms
1
1
1
Products / Services
1
1
1
1
MITRE Techniques
2
1
1
1
CVEs
68
68
60
58
50
This rule detects the creation of a new WordPress administrator account within a short window (15 minutes) of an anomalous authentication or registration event on the same account or session. It is designed to identify post-exploitation activity, specifically persistence mechanisms following the exploitation of web application vulnerabilities like arbitrary file uploads or authentication bypasses in WordPress plugins.
Detects the creation of .php files within the wp-content/uploads directory tree by common web server or PHP-FPM processes. This behavior is indicative of an adversary attempting to drop a web shell via file upload bypass vulnerabilities, such as those exploiting MIME-type manipulation.
