Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

7 detections

Detects the spawning of suspicious processes like cmd, powershell, or certutil by the Exchange Server's web worker process (w3wp.exe), which is a common indicator of post-exploitation activity following an initial web vulnerability exploitation, such as ProxyLogon.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
22 days ago
002
Detects malicious script execution triggered by the CVE-2026-42897 XSS vulnerability in Outlook Web Access (OWA). The detection rule monitors AMSI script detection events for patterns associated with the OWAReaper exploit chain, which utilizes an 'onload=eval(atob())' loader to reconstruct a base64-encoded payload embedded in social-icon image tags within a browser session.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
35055
Detects the delivery of a malicious SVG data-URI payload targeting the CVE-2026-42897 vulnerability in Outlook Web Access (OWA). This exploit uses a base64-encoded SVG image embedded in an email body, which triggers an onload JavaScript handler when rendered by OWA, leading to potential code execution within the mailbox context.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
2 months ago
36035
Detects HTTP POST requests to the OWA directory containing rule or forwarding parameters, which may indicate an attacker attempting to establish persistence via inbox rule manipulation after hijacking a session. Associated with CVE-2026-42897 post-exploitation activity.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
5 months ago
361638
Identifies potentially malicious client-side redirects or forced OAuth flows initiating from the Outlook Web Access (OWA) interface, characterized by 302 statuses and redirect parameters. This activity may indicate post-exploitation actions related to CVE-2026-42897.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
5 months ago
120492
Detects unusual JavaScript-related URI query parameters in Exchange IIS logs accessing the OWA directory. This may indicate attempted exploitation of the CVE-2026-42897 XSS vulnerability.
avatar
Ethan Andrews@eandrews
avatar
Federal Signal Detections
5 months ago
90484
Detects a temporal pattern characteristic of CVE-2026-42897 XSS exploitation: an OWA user reads a message (via Bind, OpenMessage, or similar EWS/OWA endpoints), and within 60 seconds, the same session issues a POST request to create or modify an inbox rule. This rapid succession from the same session cookie indicates programmatic action (XSS-driven JavaScript) rather than human-driven workflow. The rule correlates events by client IP and username within a 60-second window.
avatar
Tim Peck@timpeck
avatar
Detections.ai Community
5 months ago
180643