T1190 Exploit Public-Facing Application — ATT&CK Technique
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other system with Internet-accessible open sockets. On ESXi infrastructure, adversaries may exploit exposed OpenSLP services; they may alternatively exploit exposed VMware vCenter servers. Depending on the flaw being exploited, this may also involve Exploitation for Stealth or Exploitation for Client Execution. If an application is hosted on cloud-based infrastructure and/or is containerized, then exploiting it may lead to compromise of the underlying instance or container. This can allow an adversary a path to access the cloud or container APIs (e.g., via the Cloud Instance Metadata API), exploit container host access via Escape to Host, or take advantage of weak identity and access management policies. Adversaries may also exploit edge network infrastructure and related appliances, specifically targeting devices that do not support robust host-based defenses. For websites and databases, the OWASP top 10 and CWE top 25 highlight the most common web-based vulnerabilities.
Detection coverage (50)
- OMIGOD SCX RunAsProvider ExecuteScript high
- CVE-2024-50623 Exploitation Attempt - Cleo high
- Potential Exploitation of GoAnywhere MFT Vulnerability high
- Potential SAP NetWeaver Webshell Creation - Linux medium
- Cisco ASA Exploitation Activity - Proxy high
- Potential SAP NetWeaver Webshell Creation medium
- Suspicious Child Process of SAP NetWeaver - Linux medium
- Suspicious CrushFTP Child Process medium
- Potential SAP NetViewer Webshell Command Execution high
- Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators high
- Suspicious Child Process of SAP NetWeaver medium
- Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create critical
- Suspicious Child Process of SolarWinds WebHelpDesk high
- SharePoint ToolShell CVE-2025-53770 Exploitation - Web IIS medium
- Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE high
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309) high
- Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791) high
- Linux Suspicious Child Process from Node.js - React2Shell high
- Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process high
- Windows Suspicious Child Process from Node.js - React2Shell high
- Exploitation Activity of CVE-2025-59287 - WSUS Deserialization high
- Potential OGNL Injection Exploitation In JVM Based Application high
- Potential XXE Exploitation Attempt In JVM Based Application high
- Django Framework Exceptions medium
- Potential JNDI Injection Exploitation In JVM Based Application high
- Potential Local File Read Vulnerability In JVM Based Application high
- Process Execution Error In JVM Based Application high
- OpenCanary - HTTP POST Login Attempt high
- OpenCanary - HTTP GET Request high
- Potential RCE Exploitation Attempt In NodeJS high
- Python SQL Exceptions medium
- OpenCanary - FTP Login Attempt high
- Potential Server Side Template Injection In Velocity high
- Ruby on Rails Framework Exceptions medium
- Spring Framework Exceptions medium
- Potential SpEL Injection In Spring Framework high
- Ingress/Egress Security Group Modification medium
- Suspicious SQL Error Messages high
- LoadBalancer Security Group Modification medium
- Suspicious SQL Query medium
- RDS Database Security Group Modification medium
- Apache Threading Error medium
- Suspicious OpenSSH Daemon Error medium
- Suspicious Named Error high
- Suspicious VSFTPD Error Messages medium
- OMIGOD SCX RunAsProvider ExecuteShellCommand high
- DNS Query to External Service Interaction Domains high
- Java Payload Strings high
- Path Traversal Exploitation Attempts medium
- F5 BIG-IP iControl Rest API Command Execution - Proxy medium
Malware using this technique
Threat actors using this technique
- BlackByte
- Void Manticore
- Sarcoma
- DragonForce
- RedNovember
- Play Ransomware
- GALLIUM
- Kimsuky
- Volt Typhoon
- APT41
- Salt Typhoon
- APT10
- HAFNIUM
- MuddyWater
- GOLD SOUTHFIELD
- FIN7
- Sandworm Team
- APT35
- Rocke
- APT39
- UNC3886
- Moses Staff
- APT27
- Sea Turtle
- APT15
- BlackTech
- APT40
- Blue Mockingbird
- Winter Vivern
- Storm-0501
- APT29
- Cinnamon Tempest
- MirrorFace
- Medusa Ransomware
- BackdoorDiplomacy
- Axiom
- Ember Bear
- Volatile Cedar
- ToddyCat
- Agrius
- APT28
- APT5
- Fox Kitten
- INC Ransom
- Earth Lusca
- Dragonfly
- FIN13
- TeamPCP
- ShinyHunters