1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1190 Exploit Public-Facing Application — Detection Rules

Detection workspace for T1190 Exploit Public-Facing Application: 46 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1190 Exploit Public-Facing Application

MATCH(waf_exploit_signature OR ids_exploit_signature OR known_exploit_request_pattern) -> ALERT

Anomaly models

Public-facing application exploitation — T1190 Exploit Public-Facing Application

Comparison unit: request and application process.

Expected behavior: requests produce known response patterns and application behavior.

Deviation: request feature combinations, error distributions, or request-to-child-process transitions outside the normal application flow. Signature detection is often stronger for known exploits.

ATT&CK analytic guidance

DET0080 Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress)

AN0219 Analytic 0219

Adversary sends crafted HTTP/S (or other service) input to an Internet-facing app (IIS/ASP.NET, API, device portal). Chain: (1) abnormal request patterns to public endpoint → (2) elevated 4xx/5xx or unusual methods/paths → (3) server process (w3wp.exe/other service) spawns shell/LOLbins or loads non-standard modules → (4) optional outbound callback from the host/container.

AN0220 Analytic 0220

Adversary exploits Apache/Nginx/app servers. Chain: (1) suspicious requests in access logs → (2) spike of 5xx or WAF blocks → (3) web server or interpreter (apache2/nginx/php-fpm/node/python) spawns /bin/sh, curl, wget, socat, or writes webshell → (4) outbound callback.

AN0221 Analytic 0221

Adversary targets macOS-hosted public services (e.g., nginx, node). Chain: suspicious inbound request → service crash/5xx → service spawns shell or writes file → new outbound connection.

AN0222 Analytic 0222

Adversary exploits containerized app via ingress or service. Chain: (1) suspicious request in ingress/app logs → (2) container process spawns a shell/exec/sidecar (kubectl exec/docker exec) → (3) egress to Internet or metadata service (169.254.169.254).

AN0223 Analytic 0223

Adversary targets cloud-hosted public endpoints. Chain: (1) ALB/ELB/Cloud LB logs show exploit-like inputs or error spikes → (2) workload spawns shell or reaches metadata API → (3) egress to new external hosts.

AN0224 Analytic 0224

Adversary exploits exposed OpenSLP on ESXi or vCenter public endpoints. Chain: inbound request pattern to mgmt service → hostd/vpxd error/crash/restart → unexpected process behavior or datastore access → outbound callback.

AN0225 Analytic 0225

Adversary exploits public admin services on routers/firewalls/switches. Chain: anomalous HTTP/SNMP/SmartInstall inputs → device syslog errors/restarts → config changes/CLI spawn → egress to attacker C2.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1190 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.