EXPL_LOG_Cacti_CommandInjection_CVE_2022_46169_Dec22_1
Description
Detects potential exploitation attempts that target the Cacti Command Injection CVE-2022-46169
Query · yara
strings:
$xr1 = /\/remote_agent\.php.{1,300}(whoami|\/bin\/bash|\/bin\/sh|\bwget\b|powershell|cmd \/c|cmd\.exe \/c).{1,300} 200 / ascii
condition:
$xr1