mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
1.5 KiB
1.5 KiB
title, last_modified_at, toc, tags
| title | last_modified_at | toc | tags | ||||
|---|---|---|---|---|---|---|---|
| Apache Struts Vulnerability | 2018-12-06 | true |
|
Description
Detect and investigate activities--such as unusually long Content-Type length, suspicious java classes and web servers executing suspicious processes--consistent with attempts to exploit Apache Struts vulnerabilities.
- ID: 2dcfd6a2-e7d2-4873-b6ba-adaf819d2a1e
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2018-12-06
- Author: Rico Valdez, Splunk
Detection profiles
| Name | Technique | Type |
|---|---|---|
| Suspicious Java Classes | None | Anomaly |
| Unusually Long Content-Type Length | None | Anomaly |
| Web Servers Executing Suspicious Processes | None | TTP |
Reference
source | version: 1