Windows Potential Web Shell Creation For VMware Workspace ONE: endpointEndpointNoneversion:2
This analytic looks for evidence of web shells being created in the VMware Workspace ONE path on Windows or Linux systems, which has been actively exploited by attackers via CVE-2022-22954.
VMWare Aria Operations Exploit Attempt: networkWeb ServerNoneversion:10
The following analytic detects potential exploitation attempts against VMWare vRealize Network Insight, specifically targeting the CVE-2023-20887 vulnerability.
It monitors web traffic for HTTP POST requests directed at the vulnerable endpoint "/saas./resttosaasservlet." This detection leverages web traffic data, focusing on specific URL patterns and HTTP methods.
Identifying this behavior is crucial for a SOC as it indicates an active exploit attempt.
If confirmed malicious, the attacker could execute arbitrary code, leading to unauthorized access, data theft, or further network compromise.