Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

2 detections

This rule detects the creation of a new WordPress administrator account within a short window (15 minutes) of an anomalous authentication or registration event on the same account or session. It is designed to identify post-exploitation activity, specifically persistence mechanisms following the exploitation of web application vulnerabilities like arbitrary file uploads or authentication bypasses in WordPress plugins.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
407
Detects the creation of .php files within the wp-content/uploads directory tree by common web server or PHP-FPM processes. This behavior is indicative of an adversary attempting to drop a web shell via file upload bypass vulnerabilities, such as those exploiting MIME-type manipulation.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
415