Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
8 detections
Filters
Last updated
All Time
Detection languages
3
2
1
1
1
Contributors
5
1
1
1
Categories
6
5
3
3
2
Platforms
8
5
2
Products / Services
4
2
2
1
1
MITRE Techniques
6
4
4
3
2
CVEs
68
68
60
58
50
IDS Classtypes
1
IDS Protocols
1
This rule detects potential exploitation attempts targeting the Splunk REST API (CVE-2026-20253) by monitoring for unauthenticated inbound requests to the /services/ path. It specifically looks for requests that lack the required Authorization or Cookie headers.
Detects remote code execution exploitation targeting CVE-2026-20253 in Splunk. The rule monitors for unauthorized child processes, such as shells or scripting interpreters, being spawned by the Splunk daemon (splunkd). It also flags processes containing exploit-related strings in the command line as a secondary indicator.
Detects the exploitation of CVE-2026-20253, where the Flowise application fails to correctly sanitize or validate environment variables. By using a case-insensitive bypass (e.g., lowercase 'node_options'), an attacker can cause a spawned Node.js child process to honor the variable and execute unauthorized JavaScript files via the '--require' command-line argument.
Detects potential local privilege escalation activity involving AnyDesk. The rule monitors for malicious registry modifications (COM hijack), spawning of suspicious child processes by AnyDesk, creation of specific named-pipe artifacts, unsigned DLL loads from user-writable directories, and unauthorized cross-process injection, potentially linked to CVE-2026-20253.
Detects the exploitation of CVE-2026-20253, where the Flowise application fails to correctly sanitize or validate environment variables. By using a case-insensitive bypass (e.g., lowercase 'node_options'), an attacker can cause a spawned Node.js child process to honor the variable and execute unauthorized JavaScript files via the '--require' command-line argument.
Detects anomalous Firefox behavior consistent with CVE-2026-20253 exploitation, including unauthorized modification of Smart Window browser preferences (e.g., enabling the feature or redirecting the API endpoint) and suspicious child process creation following potential URL exfiltration events.
Detects potential exploitation of Firefox SmartWindow (CVE-2026-20253) involving token exfiltration via specific URL patterns, unauthorized configuration preference tampering (e.g., smartwindow.enabled, smartwindow.apiKey), or modifications to browser configuration files (prefs.js, user.js) by the Firefox process.
Detects the execution of pg_dump or pg_restore initiated by Splunk processes with unexpected remote hosts or custom directories. This behavior is indicative of CVE-2026-20253 exploitation, where an unauthenticated attacker can abuse the PostgreSQL Sidecar Service to achieve remote code execution.



