Skip to content

Commit 0392bfe

Browse files
authored
Update cisco_secure_application_alerts.yml
1 parent 6908748 commit 0392bfe

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/application/cisco_secure_application_alerts.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 9982bff4-fc5d-49a3-ab9e-2dbbab2a711b
33
version: 1
44
date: '2025-02-04'
55
author: Ryan Long, Bhavin Patel, Splunk
6-
status: experimental
6+
status: production
77
type: Anomaly
88
description: |
99
The following analytic is to leverage alerts from Cisco SecureApp, which identifies and monitors exploit attempts targeting business applications. The primary attack observed involves exploiting vulnerabilities in web applications, including injection attacks (SQL, API abuse), deserialization vulnerabilities, remote code execution attempts, LOG4J and zero day attacks. These attacks are typically aimed at gaining unauthorized access, exfiltrating sensitive data, or disrupting application functionality.

0 commit comments

Comments
 (0)