// MITRE ATT&CK

T1190 · Exploit Public-Facing Application

🎯 Initial Access ContainersESXiIaaSLinuxmacOSNetwork DevicesWindows

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like ...

¿Cómo detectarlo y mitigarlo?

La detección de Exploit Public-Facing Application parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.

Técnicas relacionadas

Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.