Using Microsoft Sentinel to Detect Confluence…
ID: 6da3de29-770a-5cd8-90eb-57a9d070aa79
STIX ID: report--6da3de29-770a-5cd8-90eb-57a9d070aa79
Feed Name: Binary Defense Blog
Threat Score
This student research project documents setting up a vulnerable Atlassian Confluence (v7.13) instance, exploiting CVE-2022-26134 (OGNL injection leading to RCE) using a C2 beacon, and developing Microsoft Sentinel log collection, Kusto parsing functions, KQL detection queries (e.g., URL-encoded '{' detection and unusual Java child processes), and Sentinel alerting rules to detect and group incidents from these exploitation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
