Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
4 detections
Filters
Last updated
All Time
Detection languages
2
1
1
Contributors
4
Categories
4
3
3
1
1
Platforms
4
1
Products / Services
3
3
MITRE Techniques
4
3
3
1
CVEs
68
68
60
58
49
Potential exploitation of JetBrains TeamCity (Unauthenticated RCE, CVE-2026-63077) looking for suspicious child processes spawned by TeamCity services.
Potential exploitation of JetBrains TeamCity (Unauthenticated RCE, CVE-2026-63077) looking for suspicious child processes spawned by TeamCity services.
Detects file creation, write, or rename operations to specific paths known to be used in exploitation of CVE-2026-63077.
Detects suspicious command-line activity originating from TeamCity service processes on Windows. The rule looks for unexpected child processes (e.g., cmd.exe, powershell.exe, curl.exe) initiated by the TeamCity server or associated Java processes, which may indicate exploitation of an unauthenticated remote code execution vulnerability.
