Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detects potential exploitation of a SAML-related vulnerability in Citrix NetScaler appliances by correlating a surge in SAML authentication traffic to Gateway/AAA endpoints followed by application crashes or core dumps on the device. This behavioral pattern is indicative of a crash-inducing exploitation attempt targeting SAML processing.
avatar
Kevin Schuster@kuroko
avatar
Detections.ai Community
2 days ago
9018