
Min Sakka
@AlphaOmegaCompletionist
0 followers80 downloads43 copies0 likes177 views
15 detections
Filters
Last updated
All Time
Detection languages
10
3
2
Categories
7
5
3
3
3
Platforms
5
4
3
2
2
Products / Services
7
4
3
2
2
MITRE Techniques
7
4
4
3
3
CVEs
3
3
2
Enumerates installed Chrome extensions, cross-references against public blocklists, and flags suspicious permissions.
This rule detects anomalies in outbound network data transfer by comparing the current daily volume of data sent to external, non-private IP addresses against the historical average for those specific sources. It alerts when the daily volume exceeds 500MB and shows a significant spike (3x or more) compared to historical baseline data or when no historical data is available for a new source connection.
Detects the forged Next.js Server Action invocation used to deliver the
RCE payload after the encryption key has been disclosed. The request is
a multipart/form-data POST containing a "$ACTION_REF_*" field together
with the numbered "$ACTION_<ref>:0/1/2" descriptor fields (action id,
argument list, base64-encoded AES-GCM ciphertext for the closure-bound
args) plus one additional attacker-controlled form field carrying the
payload. Legitimate Server Action calls originate only from the app's
own client bundle and do not normally arrive as raw multipart posts
crafted with a generic HTTP client / no browser fingerprint, especially
shortly after a manifest-disclosure request from the same source (see
companion rule "Next.js Server-Reference-Manifest Disclosure via
Backslash Path Traversal").
RCE payload after the encryption key has been disclosed. The request is
a multipart/form-data POST containing a "$ACTION_REF_*" field together
with the numbered "$ACTION_<ref>:0/1/2" descriptor fields (action id,
argument list, base64-encoded AES-GCM ciphertext for the closure-bound
args) plus one additional attacker-controlled form field carrying the
payload. Legitimate Server Action calls originate only from the app's
own client bundle and do not normally arrive as raw multipart posts
crafted with a generic HTTP client / no browser fingerprint, especially
shortly after a manifest-disclosure request from the same source (see
companion rule "Next.js Server-Reference-Manifest Disclosure via
Backslash Path Traversal").
Detects potential JWT algorithm-confusion or authentication-bypass attempts
targeting WSO2 API Manager components through JWTs specifying unsupported,
downgraded, or unexpected signing algorithms such as "none" or HS256 where
asymmetric signing is expected. Matching events should be investigated to
determine whether the request represents exploitation of CVE-2026-5430.
targeting WSO2 API Manager components through JWTs specifying unsupported,
downgraded, or unexpected signing algorithms such as "none" or HS256 where
asymmetric signing is expected. Matching events should be investigated to
determine whether the request represents exploitation of CVE-2026-5430.
Enumerates installed Chrome extensions, cross-references against public blocklists, and flags suspicious permissions.
