// MITRE ATT&CK
T1190 · Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration. Exploited applications are often websites/web servers, but can also include databases (like ...
How to detect & mitigate it
Detecting Exploit Public-Facing Application starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1195.001
Compromise Software Dependencies and Development Tools T1566.002
Spearphishing Link T1566.001
Spearphishing Attachment T1195.003
Compromise Hardware Supply Chain T1195
Supply Chain Compromise T1659
Content Injection T1199
Trusted Relationship T1566
Phishing
Compromise Software Dependencies and Development Tools T1566.002
Spearphishing Link T1566.001
Spearphishing Attachment T1195.003
Compromise Hardware Supply Chain T1195
Supply Chain Compromise T1659
Content Injection T1199
Trusted Relationship T1566
Phishing
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.