Initial Access Detection Rules
The adversary is trying to get into your network. Initial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords.
df00tech ships 222 production-ready detection rules mapped to the Initial Access tactic (TA0001). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Unlock the full Pro package
Response playbooks, investigation guides and atomic tests for every technique — from £29/mo.
Initial Access detections (222)
- CVE-2008-0015 Microsoft Windows Video ActiveX Control Remote Code Execution (CVE-2008-0015)
- CVE-2008-4250 MS08-067 NetAPI Buffer Overflow Exploitation Attempt (CVE-2008-4250)
- CVE-2009-0238 Microsoft Office Remote Code Execution (CVE-2009-0238)
- CVE-2009-0556 Microsoft Office PowerPoint Code Injection (CVE-2009-0556)
- CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability (CVE-2009-1537)
- CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow (CVE-2009-3459)
- CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability (CVE-2010-0249)
- CVE-2010-0806 CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Exploitation
- CVE-2017-7921 Hikvision Improper Authentication Exploitation (CVE-2017-7921)
- CVE-2018-4063 Sierra Wireless AirLink ALEOS Unrestricted File Upload Exploitation
- CVE-2019-19006 Sangoma FreePBX Remote Admin Authentication Bypass (CVE-2019-19006)
- CVE-2020-9715 Adobe Acrobat Use-After-Free Exploitation (CVE-2020-9715)
- CVE-2021-22681 Rockwell Automation Logix Controllers Insufficient Credential Protection (CVE-2021-22681)
- CVE-2021-26828 CVE-2021-26828: OpenPLC ScadaBR Unrestricted File Upload RCE
- CVE-2021-26829 OpenPLC ScadaBR Cross-Site Scripting (XSS) Exploitation Detected
- CVE-2021-30952 CVE-2021-30952: Apple Multiple Products Integer Overflow Exploitation
- CVE-2022-20775 CVE-2022-20775 — Cisco SD-WAN Path Traversal Exploitation Attempt
- CVE-2022-37055 CVE-2022-37055 D-Link Router Buffer Overflow Exploitation
- CVE-2022-48503 CVE-2022-48503 Apple Multiple Products Unspecified Vulnerability Exploitation
- CVE-2023-4346 KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout (CVE-2023-4346)
- CVE-2023-21529 Microsoft Exchange Server Deserialization of Untrusted Data (CVE-2023-21529)
- CVE-2023-27351 CVE-2023-27351 - PaperCut NG/MF Improper Authentication Exploitation
- CVE-2023-41974 Apple iOS/iPadOS Use-After-Free Exploitation (CVE-2023-41974)
- CVE-2023-52163 Digiever DS-2105 Pro Missing Authorization Exploitation (CVE-2023-52163)
- CVE-2024-1708 ConnectWise ScreenConnect Path Traversal (CVE-2024-1708)
- CVE-2024-3400 Palo Alto PAN-OS GlobalProtect Command Injection (CVE-2024-3400)
- CVE-2024-7399 Samsung MagicINFO 9 Server Path Traversal and Arbitrary File Upload
- CVE-2024-7694 TeamT5 ThreatSonar Anti-Ransomware Unrestricted File Upload (CVE-2024-7694)
- CVE-2024-21182 Oracle WebLogic Server CVE-2024-21182 Exploitation Attempt
- CVE-2024-21413 CVE-2024-21413: Microsoft Outlook RCE via Moniker Link (MonikerLink)
- CVE-2024-21887 Ivanti Connect Secure Authenticated Command Injection (CVE-2024-21887)
- CVE-2024-23897 CVE-2024-23897: Jenkins Arbitrary File Read via CLI Argument Parser (Pre-Auth RCE Chain)
- CVE-2024-27199 JetBrains TeamCity Relative Path Traversal (CVE-2024-27199)
- CVE-2024-30078 CVE-2024-30078: Windows Wi-Fi Driver Remote Code Execution via Adjacent Network
- CVE-2024-37079 VMware vCenter Server Out-of-bounds Write (CVE-2024-37079)
- CVE-2024-38112 CVE-2024-38112 - Windows MSHTML Spoofing via .url File Phishing (Void Banshee)
- CVE-2024-43468 CVE-2024-43468: Microsoft Configuration Manager SQL Injection Exploitation
- CVE-2024-57726 SimpleHelp Missing Authorization Vulnerability (CVE-2024-57726)
- CVE-2024-57728 SimpleHelp Path Traversal Vulnerability (CVE-2024-57728)
- CVE-2025-2746 CVE-2025-2746: Kentico Xperience CMS Authentication Bypass
- CVE-2025-2747 Kentico Xperience CMS Authentication Bypass (CVE-2025-2747)
- CVE-2025-2749 Kentico Xperience Path Traversal and Arbitrary File Upload (CVE-2025-2749)
- CVE-2025-6204 CVE-2025-6204 — Dassault Systèmes DELMIA Apriso Code Injection
- CVE-2025-6205 Dassault Systèmes DELMIA Apriso Missing Authorization (CVE-2025-6205)
- CVE-2025-6218 CVE-2025-6218: RARLAB WinRAR Path Traversal Exploitation
- CVE-2025-8110 Gogs Path Traversal Vulnerability (CVE-2025-8110)
- CVE-2025-9242 WatchGuard Firebox Out-of-Bounds Write Exploitation (CVE-2025-9242)
- CVE-2025-12480 Gladinet Triofox Improper Access Control Exploitation Detected
- CVE-2025-13223 Google Chromium V8 Type Confusion Exploitation (CVE-2025-13223)
- CVE-2025-14174 CVE-2025-14174: Google Chromium Out of Bounds Memory Access Exploitation
- CVE-2025-14611 Gladinet CentreStack and Triofox Hard-Coded Cryptographic Key Exploitation
- CVE-2025-14733 CVE-2025-14733: WatchGuard Firebox Out-of-Bounds Write Exploitation
- CVE-2025-14847 MongoDB Improper Handling of Length Parameter Inconsistency (CVE-2025-14847)
- CVE-2025-15556 Notepad++ Download of Code Without Integrity Check (CVE-2025-15556)
- CVE-2025-20393 CVE-2025-20393 — Cisco Multiple Products Improper Input Validation (KEV)
- CVE-2025-21298 CVE-2025-21298: Windows OLE RCE via Malicious RTF Document
- CVE-2025-21589 Juniper Session Smart Router Authentication Bypass (CVE-2025-21589)
- CVE-2025-24893 CVE-2025-24893 XWiki Platform Eval Injection Exploitation
- CVE-2025-26399 SolarWinds Web Help Desk Deserialization of Untrusted Data (CVE-2025-26399)
- CVE-2025-31125 CVE-2025-31125: Vite Dev Server Improper Access Control
- CVE-2025-32432 CVE-2025-32432: Craft CMS Remote Code Injection
- CVE-2025-32975 Quest KACE SMA Improper Authentication Exploitation Detected
- CVE-2025-34026 Versa Concerto Improper Authentication (CVE-2025-34026)
- CVE-2025-34291 CVE-2025-34291: Langflow Origin Validation Error Exploitation
- CVE-2025-37164 HPE OneView Code Injection Exploitation (CVE-2025-37164)
- CVE-2025-40536 SolarWinds Web Help Desk Security Control Bypass (CVE-2025-40536)
- CVE-2025-40551 CVE-2025-40551 — SolarWinds Web Help Desk Deserialization RCE
- CVE-2025-40602 CVE-2025-40602 - SonicWall SMA1000 Missing Authorization Exploitation
- CVE-2025-43520 Apple Multiple Products Classic Buffer Overflow Exploitation (CVE-2025-43520)
- CVE-2025-43529 Apple WebKit Use-After-Free Exploitation Attempt (CVE-2025-43529)
- CVE-2025-48700 Zimbra Collaboration Suite XSS Exploitation (CVE-2025-48700)
- CVE-2025-49113 RoundCube Webmail Deserialization of Untrusted Data (CVE-2025-49113)
- CVE-2025-52691 SmarterMail Unrestricted File Upload Exploitation (CVE-2025-52691)
- CVE-2025-53521 F5 BIG-IP Stack-Based Buffer Overflow Exploitation (CVE-2025-53521)
- CVE-2025-54068 Laravel Livewire Code Injection (CVE-2025-54068)
- CVE-2025-54236 Adobe Commerce / Magento Improper Input Validation (CVE-2025-54236)
- CVE-2025-54313 Prettier eslint-config-prettier Embedded Malicious Code (CVE-2025-54313)
- CVE-2025-55182 CVE-2025-55182 — Meta React Server Components Remote Code Execution
- CVE-2025-58034 Fortinet FortiWeb OS Command Injection (CVE-2025-58034)
- CVE-2025-58048 CVE-2025-58048: Paymenter Remote Code Execution via Unrestricted File Upload
- CVE-2025-58360 OSGeo GeoServer XXE Injection Exploitation Attempt
- CVE-2025-59287 Microsoft WSUS Deserialization of Untrusted Data (CVE-2025-59287)
- CVE-2025-59374 ASUS Live Update Embedded Malicious Code (CVE-2025-59374)
- CVE-2025-59718 Fortinet Multiple Products Improper Verification of Cryptographic Signature (CVE-2025-59718)
- CVE-2025-61932 Motex LANSCOPE Endpoint Manager - Improper Verification of Communication Channel Source (CVE-2025-61932)
- CVE-2025-64328 Sangoma FreePBX OS Command Injection (CVE-2025-64328)
- CVE-2025-64446 CVE-2025-64446: Fortinet FortiWeb Path Traversal Exploitation
- CVE-2025-66376 Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Exploitation
- CVE-2025-66644 Array Networks ArrayOS AG OS Command Injection (CVE-2025-66644)
- CVE-2025-67038 CVE-2025-67038 Lantronix EDS5000 Code Injection Exploitation
- CVE-2025-68461 RoundCube Webmail Cross-Site Scripting (XSS) Exploitation Attempt
- CVE-2025-68645 Synacor Zimbra Collaboration Suite PHP Remote File Inclusion (CVE-2025-68645)
- CVE-2025-68670 xrdp Unauthenticated Stack Buffer Overflow via RDP Connection Sequence (CVE-2025-68670)
- CVE-2026-0257 Palo Alto Networks PAN-OS Authentication Bypass (CVE-2026-0257)
- CVE-2026-0300 Palo Alto Networks PAN-OS Out-of-bounds Write (CVE-2026-0300)
- CVE-2026-1281 CVE-2026-1281 — Ivanti EPMM Code Injection Exploitation
- CVE-2026-1340 Ivanti EPMM Code Injection Exploitation (CVE-2026-1340)
- CVE-2026-1603 Ivanti Endpoint Manager (EPM) Authentication Bypass (CVE-2026-1603)
- CVE-2026-1731 BeyondTrust Remote Support Pre-Auth RCE (CVE-2026-1731)
- CVE-2026-2441 CVE-2026-2441: Google Chromium CSS Use-After-Free Exploitation
- CVE-2026-3055 Citrix NetScaler Out-of-Bounds Read (CVE-2026-3055)
- CVE-2026-3502 TrueConf Client Download of Code Without Integrity Check (CVE-2026-3502)
- CVE-2026-3909 Google Skia Out-of-Bounds Write (CVE-2026-3909)
- CVE-2026-3910 CVE-2026-3910: Google Chromium V8 Memory Buffer Bounds Violation
- CVE-2026-5281 CVE-2026-5281 — Google Dawn Use-After-Free Exploitation
- CVE-2026-6973 CVE-2026-6973: Ivanti EPMM Improper Input Validation Exploitation
- CVE-2026-7473 Arista EOS Incomplete Comparison Authentication Bypass (CVE-2026-7473)
- CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code (CVE-2026-8398)
- CVE-2026-9082 Drupal Core SQL Injection Exploitation (CVE-2026-9082)
- CVE-2026-10520 Ivanti Sentry OS Command Injection Exploitation (CVE-2026-10520)
- CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability (CVE-2026-11645)
- CVE-2026-12569 CVE-2026-12569 - PTC Windchill and FlexPLM Improper Input Validation / Unsafe Deserialization
- CVE-2026-15409 SonicWall SMA1000 Server-Side Request Forgery Exploitation (CVE-2026-15409)
- CVE-2026-15410 SonicWall SMA1000 Code Injection Exploitation (CVE-2026-15410)
- CVE-2026-20045 CVE-2026-20045: Cisco Unified Communications Manager Code Injection
- CVE-2026-20122 Cisco Catalyst SD-WAN Manager Privileged API Abuse (CVE-2026-20122)
- CVE-2026-20127 Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass (CVE-2026-20127)
- CVE-2026-20131 Cisco FMC/SCC Deserialization RCE Exploitation (CVE-2026-20131)
- CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20182)
- CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Output Encoding Exploitation
- CVE-2026-20253 CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function
- CVE-2026-20262 Cisco Catalyst SD-WAN Manager Path Traversal Exploitation
- CVE-2026-20700 Apple Multiple Products Buffer Overflow Exploitation (CVE-2026-20700)
- CVE-2026-20963 Microsoft SharePoint Deserialization of Untrusted Data (CVE-2026-20963)
- CVE-2026-21509 Microsoft Office Security Feature Bypass (CVE-2026-21509)
- CVE-2026-21513 CVE-2026-21513 — Microsoft MSHTML Framework Protection Mechanism Failure
- CVE-2026-21514 Microsoft Office Word Reliance on Untrusted Inputs in Security Decision (CVE-2026-21514)
- CVE-2026-21643 Fortinet FortiClient EMS SQL Injection Exploitation (CVE-2026-21643)
- CVE-2026-22719 CVE-2026-22719: VMware Aria Operations Command Injection
- CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Hard-coded Credentials Exploitation
- CVE-2026-23760 SmarterMail Authentication Bypass via Alternate Path or Channel (CVE-2026-23760)
- CVE-2026-24423 SmarterMail Missing Authentication for Critical Function (CVE-2026-24423)
- CVE-2026-24858 Fortinet Multiple Products Authentication Bypass via Alternate Path or Channel (CVE-2026-24858)
- CVE-2026-25089 Fortinet FortiSandbox OS Command Injection (CVE-2026-25089)
- CVE-2026-25108 Soliton FileZen OS Command Injection Exploitation (CVE-2026-25108)
- CVE-2026-32201 Microsoft SharePoint Server Improper Input Validation (CVE-2026-32201)
- CVE-2026-33017 CVE-2026-33017: Langflow Code Injection Vulnerability
- CVE-2026-33634 Aquasecurity Trivy Embedded Malicious Code (CVE-2026-33634)
- CVE-2026-34197 Apache ActiveMQ Improper Input Validation (CVE-2026-34197)
- CVE-2026-34621 Adobe Acrobat and Reader Prototype Pollution Vulnerability (CVE-2026-34621)
- CVE-2026-34908 CVE-2026-34908 — Ubiquiti UniFi OS Improper Access Control Exploitation
- CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Exploitation Attempt
- CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability (CVE-2026-34910)
- CVE-2026-34926 Trend Micro Apex One Directory Traversal Exploitation (CVE-2026-34926)
- CVE-2026-35273 Oracle PeopleSoft PeopleTools Missing Authentication for Critical Function (CVE-2026-35273)
- CVE-2026-35616 CVE-2026-35616 — Fortinet FortiClient EMS Improper Access Control Exploitation
- CVE-2026-39808 Fortinet FortiSandbox OS Command Injection (CVE-2026-39808)
- CVE-2026-39987 Marimo Remote Code Execution via Missing Authentication (CVE-2026-39987)
- CVE-2026-41940 CVE-2026-41940: WebPros cPanel & WHM / WP2 Missing Authentication for Critical Function
- CVE-2026-42208 BerriAI LiteLLM SQL Injection Exploitation (CVE-2026-42208)
- CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting (XSS) Exploitation
- CVE-2026-44179 CVE-2026-44179: XWiki Pro Macros RCE via Excerpt-Include Macro
- CVE-2026-44180 CVE-2026-44180: Jupyter Enterprise Gateway ContainerProcessProxy._enforce_prohibited_ids Bypass
- CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization RCE (CVE-2026-45247)
- CVE-2026-45262 FacturaScripts REST API Authenticated SQL Injection via Where::sqlColumn Parenthesis Bypass (CVE-2026-45262)
- CVE-2026-45321 TanStack Router Unspecified Vulnerability Exploitation
- CVE-2026-45579 DIRAC RequestManager eval() Remote Code Execution (CVE-2026-45579)
- CVE-2026-45659 CVE-2026-45659 Microsoft SharePoint Server Deserialization RCE
- CVE-2026-46595 CVE-2026-46595: golang.org/x/crypto/ssh VerifiedPublicKeyCallback Authentication Bypass
- CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Exploitation (CVE-2026-46817)
- CVE-2026-47391 CVE-2026-47391: PraisonAI Unauthenticated A2A LLM eval() Remote Code Execution
- CVE-2026-47393 PraisonAI Flask API Server Deployed Without Authentication (CVE-2026-47393)
- CVE-2026-47396 PraisonAI Call Server Unauthenticated Agent Access (CVE-2026-47396)
- CVE-2026-47410 PraisonAI Platform JWT Hardcoded Secret Key Token Forgery
- CVE-2026-47428 CVE-2026-47428: Vitest Browser Mode XSS via Unsanitized otelCarrier Query Parameter
- CVE-2026-47429 CVE-2026-47429: Vitest UI Server Arbitrary File Read and Execution
- CVE-2026-47668 CVE-2026-47668: DbGate Unauthenticated RCE via JSON Script Runner
- CVE-2026-48027 Nx Console Embedded Malicious Code Execution (CVE-2026-48027)
- CVE-2026-48062 CVE-2026-48062: CodeIgniter4 File Upload Extension Validation Bypass (ext_in Rule)
- CVE-2026-48282 CVE-2026-48282: Adobe ColdFusion Path Traversal Exploitation
- CVE-2026-48558 CVE-2026-48558 — SimpleHelp Authentication Bypass (CWE-347)
- CVE-2026-48749 CVE-2026-48749: Incus Arbitrary File Read/Write via rootfs Symlink in Malicious Image
- CVE-2026-48753 CVE-2026-48753: Incus S3 Multipart Upload Path Traversal Arbitrary File Write
- CVE-2026-48769 CVE-2026-48769: Incus Arbitrary File Write via Trusted Image Hash
- CVE-2026-48907 Widget Factory Joomla Content Editor Improper Access Control (CVE-2026-48907)
- CVE-2026-48908 CVE-2026-48908 - JoomShaper SP Page Builder Unrestricted File Upload
- CVE-2026-48939 iCagenda Unrestricted File Upload Exploitation (CVE-2026-48939)
- CVE-2026-49252 Deepstream Server Prototype Pollution (CVE-2026-49252)
- CVE-2026-49257 CVE-2026-49257: mcp-pinot Unauthenticated Tool Invocation via Default oauth_enabled=False
- CVE-2026-49980 Rclone RCD Unauthenticated Command Execution via Inline Remote Instantiation (CVE-2026-49980)
- CVE-2026-50551 SiYuan Attribute View Asset Cell Stored XSS to RCE (CVE-2026-50551)
- CVE-2026-50563 Fission Container Executor PodSpec Injection - Node Escape Attempt
- CVE-2026-50564 Fission Environment CRD PodSpec Passthrough Node Escape (CVE-2026-50564)
- CVE-2026-50751 Check Point Security Gateway Improper Authentication (CVE-2026-50751)
- CVE-2026-52813 Gogs Path Traversal in Organization Name Leading to RCE via Git Hooks
- CVE-2026-52831 Nuclio Cron Trigger Header/Body Command Injection (CVE-2026-52831)
- CVE-2026-53633 CVE-2026-53633: Vitest Browser Mode API RCE via CDP Proxy and Config Overwrite
- CVE-2026-53753 Crawl4AI AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE
- CVE-2026-54159 PrestaShop ps_facetedsearch PHP Object Injection Leading to Unauthenticated RCE (CVE-2026-54159)
- CVE-2026-54350 Budibase Anonymous NoSQL Operator Injection via Published-App Query Templates
- CVE-2026-54782 CoreWCF SAML Token Signature Validation Authentication Bypass (CVE-2026-54782)
- CVE-2026-55166 CVE-2026-55166: Lemur ACME SSRF and IDOR Leading to AWS IAM/PKI Compromise
- CVE-2026-56155 Microsoft AD FS Insufficient Access Control Granularity Exploitation (CVE-2026-56155)
- CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function (CVE-2026-56164)
- CVE-2026-56266 Crawl4AI Docker API Multiple Critical Vulnerabilities (File Write, SSRF, Auth Bypass, XSS, JS Execution)
- CVE-2026-56290 CVE-2026-56290: Joomlack Page Builder Improper Access Control Exploitation
- CVE-2026-56291 Balbooa Forms Unrestricted File Upload Exploitation (CVE-2026-56291)
- CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Exploitation (CVE-2026-58644)
- T1078 Valid Accounts
- T1078.001 Default Accounts
- T1078.002 Domain Accounts
- T1078.003 Local Accounts
- T1078.004 Cloud Accounts
- T1091 Replication Through Removable Media
- T1133 External Remote Services
- T1189 Drive-by Compromise
- T1190 Exploit Public-Facing Application
- T1195 Supply Chain Compromise
- T1195.001 Compromise Software Dependencies and Development Tools
- T1195.002 Compromise Software Supply Chain
- T1195.003 Compromise Hardware Supply Chain
- T1199 Trusted Relationship
- T1200 Hardware Additions
- T1566 Phishing
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1566.003 Spearphishing via Service
- T1566.004 Spearphishing Voice
- T1659 Content Injection
- T1669 Wi-Fi Networks
- THREAT-InitialAccess-PhishingMacro Phishing Document Macro Execution and Initial Access
- THREAT-VPN-CredentialStuffing VPN and Remote Access Credential Stuffing / Brute Force
Related tactics
266 detections
225 detections