Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
1
1
Platforms
1
1
1
Products / Services
1
1
MITRE Techniques
1
1
1
1
1
CVEs
68
68
60
58
50
This rule detects potentially malicious use of libcurl or curl.exe involving mTLS-related flags (e.g., --cert, --key, --cacert) in non-browser processes. It specifically flags instances where such processes perform repeated HTTPS connections to remote hosts, which may indicate exploitation of CVE-2026-8932 related to mTLS connection reuse and authentication bypass.
