logo

MDR insights: how our SOC identified & responded to CVE-2024-3400

ID: 9b5c178e-64c2-5724-ad04-db22faa936a8

STIX ID: report--9b5c178e-64c2-5724-ad04-db22faa936a8

Feed Name: Expel Blog

Threat Score
86/100

Date Published: 2024-09-05

Date Updated: 2026-04-27

Author: Brandon Overstreet; Kyle Pellett; Aaron Walton

...
...

**Executive summary:** The report documents active exploitation of CVE-2024-3400 in Palo Alto PAN-OS—an unauthenticated arbitrary file-creation and command-injection vulnerability—discovered and remediated by Expel; investigators unpacked a Sliver-based backdoor (dl.txt), observed outbound C2 connections and hourly cron persistence, and found log evidence across gpsvc.log, device_telemetry_send.log, mp-monitor.log, and syslog-system.log showing injected commands and established C2, with PAN advising immediate PAN-OS updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.