
Min Sakka
@AlphaOmegaCompletionist
0 followers80 downloads43 copies0 likes177 views
15 detections
Filters
Last updated
All Time
Detection languages
10
3
2
Categories
7
5
3
3
3
Platforms
5
4
3
2
2
Products / Services
7
4
3
2
2
MITRE Techniques
7
4
4
3
3
CVEs
3
3
2
Detects suspicious/unexpected usernames appearing in Cisco ISE access.log,
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.
Detects high-volume file download, access, or preview activity originating from known anonymous proxy services. This behavior is indicative of potential data exfiltration or unauthorized mass data collection from cloud storage applications.
Detects high-volume file download, access, or preview activity originating from known anonymous proxy services. This behavior is indicative of potential data exfiltration or unauthorized mass data collection from cloud storage applications.
Detects suspicious/unexpected usernames appearing in Cisco ISE access.log,
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.
Detects a Node.js server process (e.g. "next-server", "node.exe") spawning
cmd.exe with the "/d /s /c" flag combination, which is the pattern
produced by Node's child_process.execFileSync("cmd.exe", ["/d","/s","/c",
...]) — the exact command shape used by the CVE-2026-75604 exploit chain
to run attacker-supplied commands after a Server Action deserialization
bypass. Node applications almost never legitimately spawn cmd.exe.
cmd.exe with the "/d /s /c" flag combination, which is the pattern
produced by Node's child_process.execFileSync("cmd.exe", ["/d","/s","/c",
...]) — the exact command shape used by the CVE-2026-75604 exploit chain
to run attacker-supplied commands after a Server Action deserialization
bypass. Node applications almost never legitimately spawn cmd.exe.
Detects potential JWT algorithm-confusion or authentication-bypass attempts
targeting WSO2 API Manager components through JWTs specifying unsupported,
downgraded, or unexpected signing algorithms such as "none" or HS256 where
asymmetric signing is expected. Matching events should be investigated to
determine whether the request represents exploitation of CVE-2026-5430.
targeting WSO2 API Manager components through JWTs specifying unsupported,
downgraded, or unexpected signing algorithms such as "none" or HS256 where
asymmetric signing is expected. Matching events should be investigated to
determine whether the request represents exploitation of CVE-2026-5430.
Detects HTTP requests that use URL-encoded backslash traversal sequences
("..%5C") to walk out of a Next.js dynamic route and request the
"server-reference-manifest" file, which discloses the Server Action
encryption key. This is the reconnaissance/priming stage of CVE-2026-75604
RCE exploitation, observed against both the App Router and the Pages
Router ("/_next/data/<buildId>/.../server-reference-manifest.json").
("..%5C") to walk out of a Next.js dynamic route and request the
"server-reference-manifest" file, which discloses the Server Action
encryption key. This is the reconnaissance/priming stage of CVE-2026-75604
RCE exploitation, observed against both the App Router and the Pages
Router ("/_next/data/<buildId>/.../server-reference-manifest.json").
Detects potential JWT algorithm-confusion or authentication-bypass attempts
targeting WSO2 API Manager components through JWTs specifying unsupported,
downgraded, or unexpected signing algorithms such as "none" or HS256 where
asymmetric signing is expected. Matching events should be investigated to
determine whether the request represents exploitation of CVE-2026-5430.
targeting WSO2 API Manager components through JWTs specifying unsupported,
downgraded, or unexpected signing algorithms such as "none" or HS256 where
asymmetric signing is expected. Matching events should be investigated to
determine whether the request represents exploitation of CVE-2026-5430.
This rule detects anomalies in outbound network data transfer by comparing the current daily volume of data sent to external, non-private IP addresses against the historical average for those specific sources. It alerts when the daily volume exceeds 500MB and shows a significant spike (3x or more) compared to historical baseline data or when no historical data is available for a new source connection.
This rule detects anomalies in outbound network data transfer by comparing the current daily volume of data sent to external, non-private IP addresses against the historical average for those specific sources. It alerts when the daily volume exceeds 500MB and shows a significant spike (3x or more) compared to historical baseline data or when no historical data is available for a new source connection.
