Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
1
Platforms
1
Products / Services
1
1
MITRE Techniques
1
CVEs
68
68
58
56
50
IDS Classtypes
1
IDS Protocols
1
Detects incoming HTTP POST requests to the Zimbra OnlyOffice document handler containing path traversal sequences (e.g., '..'). This pattern is indicative of an attempt to exploit CVE-2026-93643 by manipulating document save or callback paths to access unauthorized files on the server.
