Browse Rules

Search and filter across all detection sources

18 rules

panther high python

Atlassian admin impersonated another user

Reports when an Atlassian user logs in (impersonates) another user.

sagan medium other

[EXTRAHOP] CVE-2019-11580 Atlassian Crowd Exploit

[EXTRAHOP] CVE-2019-11580 Atlassian Crowd Exploit

sagan medium other

[EXTRAHOP] CVE-2021-26084 Atlassian Confluence Exploit

[EXTRAHOP] CVE-2021-26084 Atlassian Confluence Exploit

sagan medium other

[EXTRAHOP] CVE-2022-26134 Atlassian Confluence Exploit

[EXTRAHOP] CVE-2022-26134 Atlassian Confluence Exploit

sagan medium other

[EXTRAHOP] CVE-2023-22518 Atlassian Confluence Exploit

[EXTRAHOP] CVE-2023-22518 Atlassian Confluence Exploit

sagan medium other

[EXTRAHOP] CVE-2023-22518 Atlassian Confluence Exploit Attempt

[EXTRAHOP] CVE-2023-22518 Atlassian Confluence Exploit Attempt

sagan medium other

[EXTRAHOP] CVE-2022-36804 Atlassian Bitbucket Server and Data Center Exploit

[EXTRAHOP] CVE-2022-36804 Atlassian Bitbucket Server and Data Center Exploit

sigma high sigma

Atlassian Bitbucket Command Injection Via Archive API

Detects attempts to exploit the Atlassian Bitbucket Command Injection CVE-2022-36804

sagan medium other

[EXTRAHOP] CVE-2022-36804 Atlassian Bitbucket Server and Data Center Exploit Attempt

[EXTRAHOP] CVE-2022-36804 Atlassian Bitbucket Server and Data Center Exploit Attempt

sigma high sigma

Atlassian Confluence CVE-2022-26134

Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2022-26134

sentinel high kql

Atlassian Beacon Alert

'The analytic rule creates an incident when an alert is created in Atlassian Beacon. The incident's events contains values such as alert name, alert url, actor name, actor details, worskpace id of the atlassian beacon, etc. Navigate to the alertDetailURL to view more information on recommendations and remediations.'

hayabusa high sigma

Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt

Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084

sigma high sigma

Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt

Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084

hayabusa high sigma

Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt

Detects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084

rapid7 critical sigma

Attempt to Exploit CVE-2023-22527 in Atlassian Confluence

Detects attempts to exploit a template injection vulnerability in Atlassian Confluence Data Center and Server that leads to remote code execution (CVE-2023-22527).

chronicle unknown yara-l

atlassian_confluence_download_attachments_remote_code_executiondirectory_traversal

Detects Atlassian Confluence RCE via Attachment Download. Sample regex added to detect directory traversal, it can be improved. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

splunk unknown spl

Windows Metasploit Confluence Plugin Execution

Detects the malicious java plugin execution used by metasploit for Atlassian Confluence exploitation. This usually leads to the download of meterpreter giving the actor full control over the Confluence server.

splunk unknown spl

Confluence Data Center and Server Privilege Escalation

The following analytic identifies potential exploitation attempts on a known vulnerability in Atlassian Confluence, specifically targeting the /setup/*.action* URL pattern. It leverages web logs within the Splunk 'Web' Data Model, filtering for successful accesses (HTTP status 200) to these endpoints. This activity is significant as it suggests attackers might be exploiting a privilege escalation flaw in Confluence. If confirmed malicious, it could result in unauthorized access or account creati