Product
high
advisory
Unusual Child Process Execution by Web Servers on Linux
2 rules 5 TTPs 13 IOCsThis detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.
Elastic Defend +45
persistence
execution
command-and-control
initial-access
linux
webserver
webshell
privilege-escalation
+4
2r
5t
13i
updated
medium
advisory
Bitbucket Repository Exempted from Secret Scanning
2 rules 1 TTPAn attacker may attempt to disable or bypass secret scanning on a Bitbucket repository to avoid detection of committed secrets, potentially leading to credential compromise and subsequent unauthorized access.
Bitbucket Server
attack.defense-impairment
attack.t1685
bitbucket
2r
1t