T1190

Exploit Public-Facing Application

Adversaries may attempt to take advantage of a weakness in an Internet-facing computer or program using software, data, or commands.

ATT&CK / Initial Access

The Log4Shell vulnerability (CVE-2021-44228) was widely exploited to gain initial access to servers running vulnerable versions of Log4j.

Defense strategies

  • Patch management and vulnerability scanning
  • Web Application Firewall (WAF)
  • Input validation and sanitization
  • Network segmentation
  • Least privilege access controls

Detection methods

  • Monitor for unusual web requests
  • IDS/IPS signatures for known exploits
  • Log analysis for error patterns
  • Web application honeypots

T1190 on MITRE ATT&CK ↗