Browse Rules

Search and filter across all detection sources

8 rules

rapid7 critical sigma

CVE-2024-3400 - Palo Alto Networks Firewalls Command Injection

Detects GET requests to '/global-protect/login[or]logout.esp' that indicate possible exploitation of the vulnerability CVE-2024-3400.

sagan medium other

[EXTRAHOP] CVE-2024-3400 Palo Alto Networks PAN-OS File Creation

[EXTRAHOP] CVE-2024-3400 Palo Alto Networks PAN-OS File Creation

signature-base unknown yara

EXPL_PaloAlto_CVE_2024_3400_Apr24_1 [yara]

Detects characteristics of the exploit code used in attacks against Palo Alto GlobalProtect CVE-2024-3400

sagan medium other

[EXTRAHOP] CVE-2024-3400 Palo Alto Networks PAN-OS Command Injection Attempt

[EXTRAHOP] CVE-2024-3400 Palo Alto Networks PAN-OS Command Injection Attempt

sigma high sigma

Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection

Detects potential exploitation attempts of CVE-2024-3400 - an OS command injection in Palo Alto GlobalProtect. This detection looks for suspicious strings that indicate a potential directory traversal attempt or command injection.

signature-base unknown yara

APT_UTA028_ForensicArtefacts_PaloAlto_CVE_2024_3400_Apr24_1 [yara]

Detects forensic artefacts of APT UTA028 as found in a campaign exploiting the Palo Alto CVE-2024-3400 vulnerability

signature-base unknown yara

SUSP_LNX_Base64_Exec_Apr24 [yara]

Detects suspicious base64 encoded shell commands (as seen in Palo Alto CVE-2024-3400 exploitation)

sigma medium sigma

Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection - File Creation

Detects suspicious file creations in the Palo Alto Networks PAN-OS' parent telemetry folder, which are processed by the vulnerable 'dt_curl' script if device telemetry is enabled. As said script overrides the shell-subprocess restriction, arbitrary command execution may occur by carefully crafting filenames that are escaped through this function.