kevmap

TechniquesT1190 › AN0219

AN0219 Analytic 0219

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary sends crafted HTTP/S (or other service) input to an Internet-facing app (IIS/ASP.NET, API, device portal). Chain: (1) abnormal request patterns to public endpoint → (2) elevated 4xx/5xx or unusual methods/paths → (3) server process (w3wp.exe/other service) spawns shell/LOLbins or loads non-standard modules → (4) optional outbound callback from the host/container.</p>
Detects
T1190 Exploit Public-Facing Application
Part of
DET0080 Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress)

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
ApplicationLog:IISIIS W3C logs in C:\inetpub\logs\LogFiles\W3SVC* (spikes in 5xx, RCE/SQLi/path traversal/JNDI patterns)DC0038 Application Log Content
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SysmonEventCode=7DC0016 Module Load
WinEventLog:SysmonEventCode=3, 22DC0082 Network Connection Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
PublicVIPsList of public IPs/hostnames that front apps; used to scope web log and Zeek/proxy data.
SuspiciousPatternsRegex set for exploit-like inputs (../, union select, cmd=, ${jndi:, rO0AB (Java serialization), %00, ${env:}, ${${::-j}ndi}).
ErrorRateThresholdSpike threshold for HTTP status 5xx/4xx per client or URI (e.g., >5 in 5m).
TimeWindowCorrelation horizon between request, error, process spawn, and egress (e.g., 15 minutes).
AllowedChildListKnown child processes of app pools (e.g., msbuild.exe in CI) to reduce false positives.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2009-3960Adobe BlazeDSMapped
CVE-2010-2861Adobe ColdFusionMapped
CVE-2013-0625Adobe ColdFusionMapped
CVE-2013-0629Adobe ColdFusionMapped
CVE-2013-0631Adobe ColdFusionMapped
CVE-2013-0632Adobe ColdFusionMapped
CVE-2014-6271GNU Bourne-Again Shell (Bash)Mapped
CVE-2014-7169GNU Bourne-Again Shell (Bash)Mapped
CVE-2016-10033PHP PHPMailerMapped
CVE-2016-4437Apache ShiroMapped
CVE-2017-12637SAP NetWeaverMapped
CVE-2017-5638Apache StrutsMapped
CVE-2017-9805Apache StrutsMapped
CVE-2017-9822DotNetNuke (DNN) DotNetNuke (DNN)Mapped
CVE-2018-11776Apache StrutsMapped
CVE-2018-13379Fortinet FortiOSMapped
CVE-2018-15961Adobe ColdFusionMapped
CVE-2018-4939Adobe ColdFusionMapped
CVE-2018-6789Exim EximMapped
CVE-2018-7600Drupal Drupal CoreMapped
CVE-2019-0604Microsoft SharePointMapped
CVE-2019-11634Citrix Workspace Application and Receiver for WindowsMapped
CVE-2019-1653Cisco Small Business RV320 and RV325 RoutersMapped
CVE-2019-17558Apache SolrMapped
CVE-2019-18935Progress Telerik UI for ASP.NET AJAXMapped
CVE-2020-0688Microsoft Exchange ServerMapped
CVE-2020-15505Ivanti MobileIron Multiple ProductsMapped
CVE-2020-17530Apache StrutsMapped
CVE-2020-29557D-Link DIR-825 R1 DevicesMapped
CVE-2020-5902F5 BIG-IPStale
CVE-2021-21972VMware vCenter ServerMapped
CVE-2021-21973VMware vCenter Server and Cloud FoundationMapped
CVE-2021-21975VMware vRealize Operations Manager APIMapped
CVE-2021-22005VMware vCenter ServerMapped
CVE-2021-22017VMware vCenter ServerMapped
CVE-2021-22204Perl ExiftoolMapped
CVE-2021-22205GitLab Community and Enterprise EditionsMapped
CVE-2021-22893Ivanti Pulse Connect SecureMapped
CVE-2021-22986F5 BIG-IP and BIG-IQ Centralized ManagementMapped
CVE-2021-26085Atlassian Confluence ServerMapped
CVE-2021-26858Microsoft Exchange ServerMapped
CVE-2021-27065Microsoft Exchange ServerMapped
CVE-2021-27102Accellion FTAMapped
CVE-2021-27103Accellion FTAMapped
CVE-2021-27104Accellion FTAMapped
CVE-2021-27860FatPipe WARP, IPVPN, and MPVPN softwareMapped
CVE-2021-31166Microsoft HTTP Protocol StackMapped
CVE-2021-3129Laravel IgnitionMapped
CVE-2021-34473Microsoft Exchange ServerMapped
CVE-2021-34523Microsoft Exchange ServerMapped
CVE-2021-35394Realtek Jungle Software Development Kit (SDK)Mapped
CVE-2021-35464ForgeRock Access Management (AM)Mapped
CVE-2021-36380Sunhillo SureLineMapped
CVE-2021-37415Zoho ManageEngine ServiceDesk Plus (SDP)Mapped
CVE-2021-39144XStream XStreamMapped
CVE-2021-39226Grafana Labs GrafanaMapped
CVE-2021-40539Zoho ManageEngineMapped
CVE-2021-40655D-Link DIR-605 RouterMapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter PlusMapped
CVE-2021-44228Apache Log4j2Mapped
CVE-2021-44515Zoho Desktop CentralMapped
CVE-2021-44529Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA)Mapped
CVE-2021-45382D-Link Multiple RoutersMapped
CVE-2022-0028Palo Alto Networks PAN-OSMapped
CVE-2022-1040Sophos FirewallMapped
CVE-2022-20700Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-20708Cisco Small Business RV160, RV260, RV340, and RV345 Series RoutersMapped
CVE-2022-20821Cisco IOS XRMapped
CVE-2022-22947VMware Spring Cloud GatewayMapped
CVE-2022-22963VMware Tanzu Spring CloudMapped
CVE-2022-22965VMware Spring FrameworkMapped
CVE-2022-23131Zabbix FrontendMapped
CVE-2022-24086Adobe Commerce and Magento Open SourceMapped
CVE-2022-26134Atlassian Confluence Server/Data CenterMapped
CVE-2022-26258D-Link DIR-820LMapped
CVE-2022-26500Veeam Backup & ReplicationMapped
CVE-2022-26501Veeam Backup & ReplicationMapped
CVE-2022-28810Zoho ManageEngineMapped
CVE-2022-29464WSO2 Multiple ProductsMapped
CVE-2022-35914Teclib GLPIMapped
CVE-2022-36804Atlassian Bitbucket Server and Data CenterMapped
CVE-2022-39197Fortra Cobalt StrikeMapped
CVE-2022-40684Fortinet Multiple ProductsMapped
CVE-2022-42475Fortinet FortiOSMapped
CVE-2022-42948Fortra Cobalt StrikeMapped
CVE-2022-43939Hitachi Vantara Pentaho Business Analytics (BA) ServerMapped
CVE-2022-47966Zoho ManageEngineMapped
CVE-2023-0669Fortra GoAnywhere MFTMapped
CVE-2023-20198Cisco IOS XE Web UIMapped
CVE-2023-20887VMware Aria Operations for NetworksMapped
CVE-2023-22515Atlassian Confluence Data Center and ServerMapped
CVE-2023-22518Atlassian Confluence Data Center and ServerMapped
CVE-2023-22952SugarCRM Multiple ProductsStale
CVE-2023-26359Adobe ColdFusionMapped
CVE-2023-26360Adobe ColdFusionMapped
CVE-2023-27350PaperCut MF/NGMapped
CVE-2023-27524Apache SupersetMapped
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPNMapped
CVE-2023-29298Adobe ColdFusionMapped
CVE-2023-29300Adobe ColdFusionMapped
CVE-2023-29492Novi Survey Novi SurveyMapped
CVE-2023-33246Apache RocketMQMapped
CVE-2023-34362Progress MOVEit TransferMapped
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2023-3519Citrix NetScaler ADC and NetScaler GatewayMapped
CVE-2023-36844Juniper Junos OSMapped
CVE-2023-36845Juniper Junos OSMapped
CVE-2023-36846Juniper Junos OSMapped
CVE-2023-36847Juniper Junos OSMapped
CVE-2023-36851Juniper Junos OSMapped
CVE-2023-38035Ivanti SentryMapped
CVE-2023-38203Adobe ColdFusionMapped
CVE-2023-38205Adobe ColdFusionMapped
CVE-2023-38950ZKTeco BioTimeMapped
CVE-2023-42793JetBrains TeamCityMapped
CVE-2023-44487IETF HTTP/2Mapped
CVE-2023-46604Apache ActiveMQMapped
CVE-2023-46805Ivanti Connect Secure and Policy SecureMapped
CVE-2023-48365Qlik SenseMapped
CVE-2023-48788Fortinet FortiClient EMSMapped
CVE-2023-49103ownCloud ownCloud graphapiMapped
CVE-2023-7101Spreadsheet::ParseExcel Spreadsheet::ParseExcelMapped
CVE-2024-0769D-Link DIR-859 RouterMapped
CVE-2024-13159Ivanti Endpoint Manager (EPM)Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM)Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM)Mapped
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Mapped
CVE-2024-20953Oracle Agile Product Lifecycle Management (PLM)Mapped
CVE-2024-21762Fortinet FortiOSMapped
CVE-2024-21887Ivanti Connect Secure and Policy SecureMapped
CVE-2024-21893Ivanti Connect Secure, Policy Secure, and NeuronsMapped
CVE-2024-27198JetBrains TeamCityMapped
CVE-2024-34102Adobe Commerce and Magento Open SourceMapped
CVE-2024-38475Apache HTTP ServerMapped
CVE-2024-4358Progress Telerik Report ServerMapped
CVE-2024-4577PHP Group PHPMapped
CVE-2024-48248NAKIVO Backup and ReplicationMapped
CVE-2024-4879ServiceNow Utah, Vancouver, and Washington DC Now PlatformMapped
CVE-2024-55550Mitel MiCollabMapped
CVE-2024-57727SimpleHelp SimpleHelpMapped
CVE-2025-0108Palo Alto Networks PAN-OSMapped
CVE-2025-0282Ivanti Connect Secure, Policy Secure, and ZTA GatewaysMapped
CVE-2025-1316Edimax IC-7100 IP CameraMapped
CVE-2025-22457Ivanti Connect Secure, Policy Secure, and ZTA GatewaysMapped
CVE-2025-23006SonicWall SMA1000 AppliancesMapped
CVE-2025-25257Fortinet FortiWebMapped
CVE-2025-34028Commvault Command CenterMapped
CVE-2025-35939Craft CMS Craft CMSMapped
CVE-2025-42599Qualitia Active! MailMapped
CVE-2025-42999SAP NetWeaverMapped
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM)Mapped
CVE-2025-49704Microsoft SharePointMapped
CVE-2025-49706Microsoft SharePointMapped
CVE-2025-53770Microsoft SharePointMapped
CVE-2025-5777Citrix NetScaler ADC and GatewayMapped