Tag
Authenticated Full-Read SSRF in CloudTAK /api/esri* Routes
1 rule 3 TTPs 2 IOCsAn authenticated Server-Side Request Forgery (SSRF) vulnerability exists in CloudTAK's `/api/esri*` routes, allowing any authenticated user to compel the server to make arbitrary outbound HTTP requests to internal network resources, enabling attackers to access sensitive cloud instance metadata, enumerate internal services, and exfiltrate data by reflecting the response bodies.
Windows Netsh Tool Used for Firewall Discovery
2 rules 1 TTPThe native Windows `netsh.exe` tool is being abused to discover firewall configurations, potentially to weaken defenses before lateral movement and data exfiltration.
Linux System Network Discovery via Multiple Utilities
2 rules 1 TTPAdversaries may attempt to enumerate local network configurations on Linux systems using common utilities like arp, ifconfig, ip, netstat, firewall-cmd, ufw, iptables, ss, and route to gather information for reconnaissance and subsequent attacks, leading to network mapping and vulnerability identification.
Detect Windows Netspy Network Scanner Execution
2 rules 2 TTPsThe Netspy network scanner, a tool for internal network discovery, is executed on a Windows endpoint to enumerate active hosts and services, potentially for reconnaissance purposes.