| splunk |
Citrix ADC and Gateway CitrixBleed 2 Memory Disclosure |
production |
2026-05-13 |
| splunk |
Citrix ADC and Gateway Unauthorized Data Disclosure |
production |
2026-05-13 |
| splunk |
Citrix ShareFile Exploitation CVE-2023-24489 |
production |
2026-05-13 |
| splunk |
Disabled Kerberos Pre-Authentication Discovery With Get-ADUser |
production |
2026-05-13 |
| splunk |
Confluence CVE-2023-22515 Trigger Vulnerability |
production |
2026-05-13 |
| splunk |
Confluence Data Center and Server Privilege Escalation |
production |
2026-05-13 |
| splunk |
Confluence Pre-Auth RCE via OGNL Injection CVE-2023-22527 |
production |
2026-05-13 |
| splunk |
Confluence Unauthenticated Remote Code Execution CVE-2022-26134 |
production |
2026-05-13 |
| splunk |
ConnectWise ScreenConnect Authentication Bypass |
production |
2026-05-13 |
| splunk |
Detect attackers scanning for vulnerable JBoss servers |
experimental |
2026-05-13 |
| splunk |
Detect malicious requests to exploit JBoss servers |
experimental |
2026-05-13 |
| splunk |
Detect Web Access to Decommissioned S3 Bucket |
experimental |
2026-05-13 |
| splunk |
Exploit Public Facing Application via Apache Commons Text |
production |
2026-05-13 |
| splunk |
Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 |
production |
2026-05-13 |
| splunk |
F5 TMUI Authentication Bypass |
production |
2026-05-13 |
| splunk |
Fortinet Appliance Auth bypass |
production |
2026-05-13 |
| splunk |
High Volume of Bytes Out to Url |
production |
2026-05-13 |
| splunk |
HTTP Duplicated Header |
production |
2026-05-13 |
| splunk |
HTTP Possible Request Smuggling |
production |
2026-05-13 |
| splunk |
Disabled Kerberos Pre-Authentication Discovery With PowerView |
production |
2026-05-13 |
| splunk |
Hunting for Log4Shell |
production |
2026-05-13 |
| splunk |
Ivanti Connect Secure Command Injection Attempts |
production |
2026-05-13 |
| splunk |
Ivanti Connect Secure SSRF in SAML Component |
production |
2026-05-13 |
| splunk |
Ivanti Connect Secure System Information Access via Auth Bypass |
production |
2026-05-13 |
| splunk |
Ivanti EPM SQL Injection Remote Code Execution |
production |
2026-05-13 |
| splunk |
Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078 |
production |
2026-05-13 |
| splunk |
Zscaler Virus Download threat blocked |
production |
2026-05-13 |
| splunk |
Disabling CMD Application |
production |
2026-05-13 |
| splunk |
Disabling ControlPanel |
production |
2026-05-13 |
| splunk |
Disabling Defender Services |
production |
2026-05-13 |
| splunk |
Disabling Firewall with Netsh |
production |
2026-05-13 |
| splunk |
Disabling FolderOptions Windows Feature |
production |
2026-05-13 |
| splunk |
Disabling NoRun Windows App |
production |
2026-05-13 |
| splunk |
Disabling Remote User Account Control |
production |
2026-05-13 |
| splunk |
Disabling SystemRestore In Registry |
production |
2026-05-13 |
| splunk |
Disabling Task Manager |
production |
2026-05-13 |
| splunk |
Disabling Windows Local Security Authority Defences via Registry |
production |
2026-05-13 |
| splunk |
DLLHost with no Command Line Arguments with Network |
production |
2026-05-13 |
| splunk |
DNS Exfiltration Using Nslookup App |
production |
2026-05-13 |
| splunk |
Domain Account Discovery with Dsquery |
production |
2026-05-13 |