• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Potential TrueConf Server Exploitation, Web-Shell Deployment, or Installer Replacement

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Syed Usfar Wasim@nCD24
    •updated Aug 10, 2026•2•0•3

    This KQL detects attack used TCP port 4307 for unauthenticated access and replaced public\js\locale.php with a web shell that provided persistent remote access.

    Microsoft Sentinel (KQL)

    Tags

    T1190 - Exploit Public-Facing ApplicationT1505.003 - Web ShellT1059.003 - Windows Command ShellT1059.001 - PowerShellT1059.005 - Visual BasicT1218 - System Binary Proxy ExecutionT1218.005 - MshtaT1218.010 - Regsvr32DET0475 - Detection Strategy for T1218.011 Rundll32 AbuseT1105 - Ingress Tool TransferT1095 - Non-Application Layer ProtocolT1033 - System Owner/User DiscoveryT1016 - System Network Configuration DiscoveryT1087.001 - Local AccountT1069.002 - Domain GroupsT1069.001 - Local GroupsT1543.003 - Windows Servicekql

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?