avatar

Min Sakka

@AlphaOmega
Completionist
0 followers80 downloads43 copies0 likes177 views

15 detections

Detects suspicious/unexpected usernames appearing in Cisco ISE access.log,
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
15023
Detects high-volume file download, access, or preview activity originating from known anonymous proxy services. This behavior is indicative of potential data exfiltration or unauthorized mass data collection from cloud storage applications.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
20 days ago
9023
Detects high-volume file download, access, or preview activity originating from known anonymous proxy services. This behavior is indicative of potential data exfiltration or unauthorized mass data collection from cloud storage applications.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
6015
Detects suspicious/unexpected usernames appearing in Cisco ISE access.log,
consistent with exploitation of CVE-2026-76460, an unauthenticated REST API
auth-bypass in Cisco ISE / ISE-PIC (CVSS 10.0, actively exploited, CISA KEV).
Cisco's own guidance is to hunt access.log for usernames not present in the
legitimate identity store; "dummyuser" is their published example artifact.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
1014
Detects a Node.js server process (e.g. "next-server", "node.exe") spawning
cmd.exe with the "/d /s /c" flag combination, which is the pattern
produced by Node's child_process.execFileSync("cmd.exe", ["/d","/s","/c",
...]) — the exact command shape used by the CVE-2026-75604 exploit chain
to run attacker-supplied commands after a Server Action deserialization
bypass. Node applications almost never legitimately spawn cmd.exe.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
007
Detects potential JWT algorithm-confusion or authentication-bypass attempts
targeting WSO2 API Manager components through JWTs specifying unsupported,
downgraded, or unexpected signing algorithms such as "none" or HS256 where
asymmetric signing is expected. Matching events should be investigated to
determine whether the request represents exploitation of CVE-2026-5430.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
20 days ago
109
Detects HTTP requests that use URL-encoded backslash traversal sequences
("..%5C") to walk out of a Next.js dynamic route and request the
"server-reference-manifest" file, which discloses the Server Action
encryption key. This is the reconnaissance/priming stage of CVE-2026-75604
RCE exploitation, observed against both the App Router and the Pages
Router ("/_next/data/<buildId>/.../server-reference-manifest.json").
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
004
Detects potential JWT algorithm-confusion or authentication-bypass attempts
targeting WSO2 API Manager components through JWTs specifying unsupported,
downgraded, or unexpected signing algorithms such as "none" or HS256 where
asymmetric signing is expected. Matching events should be investigated to
determine whether the request represents exploitation of CVE-2026-5430.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
104
This rule detects anomalies in outbound network data transfer by comparing the current daily volume of data sent to external, non-private IP addresses against the historical average for those specific sources. It alerts when the daily volume exceeds 500MB and shows a significant spike (3x or more) compared to historical baseline data or when no historical data is available for a new source connection.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
21 days ago
007
This rule detects anomalies in outbound network data transfer by comparing the current daily volume of data sent to external, non-private IP addresses against the historical average for those specific sources. It alerts when the daily volume exceeds 500MB and shows a significant spike (3x or more) compared to historical baseline data or when no historical data is available for a new source connection.
avatar
Min Sakka@AlphaOmega
avatar
Detections.ai Community
18 days ago
003