Suspicious Tomcat Confluence Process Launch

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


The query checks for suspicious Tomcat process launches associated with likely exploitation of Confluence - CVE-2022-26134 Read more here:. https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html https://nvd.nist.gov/vuln/detail/CVE-2022-26134 Tags: #exploit #CVE-2022-26134

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 500e4cf1-9c25-4dfa-88f1-a23d95407e35
Tactics Execution, Privilege Escalation
Techniques T1203
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DeviceProcessEvents ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries