logo

Using Microsoft Sentinel to Detect Confluence…

ID: 6da3de29-770a-5cd8-90eb-57a9d070aa79

STIX ID: report--6da3de29-770a-5cd8-90eb-57a9d070aa79

Feed Name: Binary Defense Blog

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

This student research project documents setting up a vulnerable Atlassian Confluence (v7.13) instance, exploiting CVE-2022-26134 (OGNL injection leading to RCE) using a C2 beacon, and developing Microsoft Sentinel log collection, Kusto parsing functions, KQL detection queries (e.g., URL-encoded '{' detection and unusual Java child processes), and Sentinel alerting rules to detect and group incidents from these exploitation attempts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.