oracle_weblogic_exploit
Description
Detects access to a webshell droped into a keytore folder on the WebLogic server License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
Query · yara_l
events:
re.regex($selection.target.url, `.*/config/keystore/.*\.js.*`)
condition:
$selection