T1190 Exploit Public-Facing Application — Detection & Response
Adversaries may attempt to take advantage of a weakness in an Internet-facing computer or program using a software, data, or commands in order to cause unintended or unanticipated behavior. The weakness in the system can be a bug, a glitch, or a design vulnerability.
Coverage at a glance
- Detections shipped
- 4
- Avg. verdict time
- < 5 min
- Data sources
- 4+
Threat context
How adversaries use T1190 Exploit Public-Facing Application — Detection & Response
Adversaries may attempt to take advantage of a weakness in an Internet-facing computer or program using a software, data, or commands in order to cause unintended or unanticipated behavior. The weakness in the system can be a bug, a glitch, or a design vulnerability.
Web application exploitation is the second most common initial access vector after phishing. CVEs in VPN appliances (Fortinet, Citrix, Pulse Secure), web frameworks (Log4Shell, Spring4Shell), and enterprise applications are weaponised within days of disclosure. Nation-state groups frequently exploit N-day vulnerabilities against unpatched organisations. Successful exploitation typically leads to command execution, webshell deployment, and rapid privilege escalation before defenders notice.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| WAF SQL Injection Blocked — WAF blocks SQL injection pattern WAF blocks a request matching SQL injection patterns — useful for situational awareness of targeted scanning. | Medium | Cloudflare / AWS WAF |
| Web Server Spawning Shell — Web server process creates interactive shell Apache, Nginx, Tomcat, or IIS spawns a shell (bash, cmd.exe, sh) — highly anomalous and indicates successful code execution via web exploitation. | Critical | CrowdStrike / SentinelOne |
| Log4Shell Exploitation Pattern — JNDI lookup string in HTTP request parameters HTTP request contains ${jndi: string, the hallmark of Log4Shell (CVE-2021-44228) exploitation attempts. | Critical | WAF / Application Logs |
| Critical Vulnerability Unpatched on Internet-Facing Host — Wiz or Tenable finding on exposed host A CVSS 9.0+ vulnerability with public exploit code is present on an internet-facing host with no patch applied. | High | Wiz / Tenable |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1190 Exploit Public-Facing Application — Detection & Response: frequently asked questions
How does ManySignal correlate WAF alerts with post-exploitation activity?
ManySignal creates a unified timeline for each host. When a WAF alert fires for a host, ManySignal monitors subsequent endpoint events (new processes, network connections, file writes) from that host for post-exploitation patterns, enabling rapid detection of successful exploitation that bypassed the WAF.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.