THL DETECT Ivanti-Connect-Secure CVE-2024-21887 Command Injection via cac-status (Post-Auth-Bypass Command Execution Attempt)

SID: 3500170Rev: 1Enabled8 views
Filehunters-ledger.rules
CreatedJuly 27, 2026
UpdatedJuly 27, 2026
Classificationweb-application-attack
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"THL DETECT Ivanti-Connect-Secure CVE-2024-21887 Command Injection via cac-status (Post-Auth-Bypass Command Execution Attempt)"; flow:established,to_server; http.uri; content:"/cac/status?id=$("; classtype:web-application-attack; sid:3500170; rev:1; metadata:author The_Hunters_Ledger, date 2026-07-17, reference https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/;)

Metadata

authorThe_Hunters_Ledger
date2026-07-17
referencehttps://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!