Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
7 detections
Filters
Last updated
All Time
Detection languages
5
1
1
Contributors
5
1
1
Categories
6
3
2
1
1
Platforms
4
2
2
1
Products / Services
6
5
1
1
1
MITRE Techniques
3
3
3
2
2
CVEs
68
68
60
58
50
Detects the spawning of suspicious processes like cmd, powershell, or certutil by the Exchange Server's web worker process (w3wp.exe), which is a common indicator of post-exploitation activity following an initial web vulnerability exploitation, such as ProxyLogon.
Detects malicious script execution triggered by the CVE-2026-42897 XSS vulnerability in Outlook Web Access (OWA). The detection rule monitors AMSI script detection events for patterns associated with the OWAReaper exploit chain, which utilizes an 'onload=eval(atob())' loader to reconstruct a base64-encoded payload embedded in social-icon image tags within a browser session.
Detects the delivery of a malicious SVG data-URI payload targeting the CVE-2026-42897 vulnerability in Outlook Web Access (OWA). This exploit uses a base64-encoded SVG image embedded in an email body, which triggers an onload JavaScript handler when rendered by OWA, leading to potential code execution within the mailbox context.
Detects HTTP POST requests to the OWA directory containing rule or forwarding parameters, which may indicate an attacker attempting to establish persistence via inbox rule manipulation after hijacking a session. Associated with CVE-2026-42897 post-exploitation activity.
Identifies potentially malicious client-side redirects or forced OAuth flows initiating from the Outlook Web Access (OWA) interface, characterized by 302 statuses and redirect parameters. This activity may indicate post-exploitation actions related to CVE-2026-42897.
Detects unusual JavaScript-related URI query parameters in Exchange IIS logs accessing the OWA directory. This may indicate attempted exploitation of the CVE-2026-42897 XSS vulnerability.
Detects a temporal pattern characteristic of CVE-2026-42897 XSS exploitation: an OWA user reads a message (via Bind, OpenMessage, or similar EWS/OWA endpoints), and within 60 seconds, the same session issues a POST request to create or modify an inbox rule. This rapid succession from the same session cookie indicates programmatic action (XSS-driven JavaScript) rather than human-driven workflow. The rule correlates events by client IP and username within a 60-second window.


