M ManySignal
T1190 MITRE ATT&CK

T1190 Exploit Public-Facing Application — Detection & Response

Adversaries may attempt to take advantage of a weakness in an Internet-facing computer or program using a software, data, or commands in order to cause unintended or unanticipated behavior. The weakness in the system can be a bug, a glitch, or a design vulnerability.

Coverage at a glance

Detections shipped
4
Avg. verdict time
< 5 min
Data sources
4+

Threat context

How adversaries use T1190 Exploit Public-Facing Application — Detection & Response

Adversaries may attempt to take advantage of a weakness in an Internet-facing computer or program using a software, data, or commands in order to cause unintended or unanticipated behavior. The weakness in the system can be a bug, a glitch, or a design vulnerability.

Web application exploitation is the second most common initial access vector after phishing. CVEs in VPN appliances (Fortinet, Citrix, Pulse Secure), web frameworks (Log4Shell, Spring4Shell), and enterprise applications are weaponised within days of disclosure. Nation-state groups frequently exploit N-day vulnerabilities against unpatched organisations. Successful exploitation typically leads to command execution, webshell deployment, and rapid privilege escalation before defenders notice.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

WAF SQL Injection Blocked — WAF blocks SQL injection pattern

WAF blocks a request matching SQL injection patterns — useful for situational awareness of targeted scanning.

Medium Cloudflare / AWS WAF

Web Server Spawning Shell — Web server process creates interactive shell

Apache, Nginx, Tomcat, or IIS spawns a shell (bash, cmd.exe, sh) — highly anomalous and indicates successful code execution via web exploitation.

Critical CrowdStrike / SentinelOne

Log4Shell Exploitation Pattern — JNDI lookup string in HTTP request parameters

HTTP request contains ${jndi: string, the hallmark of Log4Shell (CVE-2021-44228) exploitation attempts.

Critical WAF / Application Logs

Critical Vulnerability Unpatched on Internet-Facing Host — Wiz or Tenable finding on exposed host

A CVSS 9.0+ vulnerability with public exploit code is present on an internet-facing host with no patch applied.

High Wiz / Tenable

T1190 Exploit Public-Facing Application — Detection & Response: frequently asked questions

How does ManySignal correlate WAF alerts with post-exploitation activity?

ManySignal creates a unified timeline for each host. When a WAF alert fires for a host, ManySignal monitors subsequent endpoint events (new processes, network connections, file writes) from that host for post-exploitation patterns, enabling rapid detection of successful exploitation that bypassed the WAF.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.