avatar

Kevin Schuster

@kuroko
0 followers0 downloads9 copies0 likes17 views

1 detection

Detects potential exploitation of a SAML-related vulnerability in Citrix NetScaler appliances by correlating a surge in SAML authentication traffic to Gateway/AAA endpoints followed by application crashes or core dumps on the device. This behavioral pattern is indicative of a crash-inducing exploitation attempt targeting SAML processing.
avatar
Kevin Schuster@kuroko
avatar
Detections.ai Community
2 days ago
9017