Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
1
Platforms
1
Products / Services
1
MITRE Techniques
1
1
1
CVEs
68
68
60
58
50
Detects potential exploitation of a SAML-related vulnerability in Citrix NetScaler appliances by correlating a surge in SAML authentication traffic to Gateway/AAA endpoints followed by application crashes or core dumps on the device. This behavioral pattern is indicative of a crash-inducing exploitation attempt targeting SAML processing.
