T1190
Exploit Public-Facing Application
Adversaries may attempt to take advantage of a weakness in an Internet-facing computer or program using software, data, or commands.
ATT&CK / Initial Access
The Log4Shell vulnerability (CVE-2021-44228) was widely exploited to gain initial access to servers running vulnerable versions of Log4j.
Defense strategies
- Patch management and vulnerability scanning
- Web Application Firewall (WAF)
- Input validation and sanitization
- Network segmentation
- Least privilege access controls
Detection methods
- Monitor for unusual web requests
- IDS/IPS signatures for known exploits
- Log analysis for error patterns
- Web application honeypots
D3FEND mappings
4