
KQL-Erkennungsregeln für Microsoft Sentinel und Defender XDR, die die bikini/exploitarium anonyme Offenlegung abdecken — ein persönliches Forschungsarchiv von über 15 verschiedenen Schwachstellenzielen in über 109+ nachverfolgten Dateien, veröffentlicht ohne Benachrichtigung der Anbieter am 23. Juni 2026.
KQL-Erkennungsregeln für Microsoft Sentinel und Defender XDR, die die bikini/exploitarium-Veröffentlichung abdecken – ein persönliches Forschungsarchiv mit über 15 verschiedenen Schwachstellenzielen in über 109 verfolgten Dateien, veröffentlicht ohne Benachrichtigung der Hersteller am 23. Juni 2026.
54 Regeln | 23 Produktordner | KQL | Autor: Ethan Andrews (@eandrews)
Zuletzt aktualisiert: 1. Juli 2026
Intel-Bericht: https://systemtwosecurity.com/share/inspiration/VNJMKFVM
Ein anonymer Forscher namens 'bikini' hat exploitarium veröffentlicht, ein GitHub-Repository mit Proof-of-Concept-Forschung zu über 15 verschiedenen Schwachstellenzielen (109+ verfolgte Dateien in 15+ Ordnern). Das Repository wird aktiv aktualisiert – neue Einträge werden hinzugefügt, sobald der Forscher weiterhin Arbeiten veröffentlicht.
Klarstellung zum Umfang: Das Repository enthält 15 verschiedene Schwachstellenforschungsziele. Die Dateianzahlen pro Ordner spiegeln einzelne Dateien wider (Skripte, Payloads, Hilfsprogramme, READMEs) – nicht einzelne CVEs. Der Forscher stellt im README fest, dass diese zum Zeitpunkt der Veröffentlichung nicht gemeldet waren, und lädt ausdrücklich andere ein, CVEs einzureichen.
Die technisch bedeutsamsten Erkenntnisse – ein libssh2-Heap-Write vor der Authentifizierung und eine Gitea-Standard-Docker-Authentifizierungsumgehung – wurden unabhängig als hochriskant bestätigt, wobei aktive Ausnutzung beobachtet wurde. Einige Einträge wurden von der Community als einkommensschwaches Rauschen abgetan.
Exploitarium-Detections/
├── 7zip/ # MOTW-Bypass x3 (Regeln 02, 27, 28)
├── anydesk/ # COM-Hijack-DLL, Named Pipe, PE-Fingerabdruck-Recon (Regeln 06, 17, 36)
├── c-ares/ # TCP-UAF-NDR-Sequenz, Linkage-Recon, DNS-Ausfallspitze (Regeln 07, 08, 41)
├── curl/ # SMTP-CRLF-Injektionsversuch + PoC-Artefakt (Regeln 45, 46)
├── docker/ # Privilegierter Container-Host-Mount-Shell-Spawn (Regel 38)
├── exploitarium-generic/ # calc.exe-PoC-generisch, Multi-CVE-Scan (Regeln 22, 44)
├── ffmpeg/ # (reserviert)
├── firefox/ # SmartWindow-stilles Aktivieren (Regel 09)
├── flowise/ # Unautorisierter API-Zugriff (Regel 37)
├── ghidra/ # Headless-Analyzer, verdächtige Skriptausführung (Regel 40)
├── imagemagick/ # Policy-Bypass-Delegatenausführung (Regel 39)
├── libarchive/ # ZIP-debuginfod-Größen-Grenzumgehung x2 (Regeln 51, 52)
├── libssh2/ # Pre-Auth-RCE, DoS x2, Scaffold x2, Heap-Korruption, Recon (Regeln 01, 12, 13, 24, 25, 26, 35)
├── lunar-client/ # Electron-IPC-Preload, Modrinth-gameDirectory-Missbrauch (Regeln 15, 16)
├── mybb/ # ACP-Privilegieneskalation x2 (Regeln 05, 21)
├── nextjs/ # unstable_cache PoC-Ausführung, Cache-Objekt-Kollision (Regeln 49, 50)
├── nmap/ # IPv6-ExtLen-Wrap-PoC (Regel 18)
├── nodebb/ # ActivityPub-UID-Spoof x2 (Regeln 47, 48)
├── openvpn/ # PAC-Injektion, Echo-Script-ACE, DHCP-Options-Injektion (Regeln 14, 42, CVE-2026-45115)
├── php/ # SOAP-RCE, ASLR-Bypass (Regeln 10, 11)
├── pillow/ # ImageCms-OOB-Write-PoC-Ausführung + Absturzerkennung (Regeln 53, 54, 55)
├── rustdesk/ # Sitzungsumgehung x4 (Regeln 03, 19, 23, 33, 34)
├── splunk/ # splunkd-Kindprozess, Reverse-Shell, REST-API, PoC-Artefakt (Regeln 20, 31, 32, 43)
└── vlc/ # VP9-Absturz/Kind-Spawn, WER-Bericht, VP9-Decode-Kind (Regeln 04, 29, 30)
libssh2/cve-2026-55200-pre-auth-rce-child-process.kql — CVSS 9.2, aktive Ausnutzunglibssh2/libssh2-linkage-recon-ldd-readelf-strings.kql — Erkennung von Recon vor der Ausnutzunglibssh2/cve-2026-55200-libpwn-harness-binaries-endpoint.kql — Harness-Binärdateien auf der Festplatteexploitarium-generic/multi-cve-exploitarium-sweep-simultaneous-poc.kql — breitester Scansplunk/cve-2026-20253-splunkd-unexpected-child-process.kql — hochwertiges Unternehmenszielrustdesk/rustdesk-session-permission-bypass-comprehensive.kql — vollständige Multi-Branch-Abdeckungcurl/curl-smtp-expn-crlf-injection-attempt.kql — relevant für jedes E-Mail-sendende SaaS unter Verwendung von libcurlJede .kql-Datei enthält den vollständigen Regelkörper plus einen Metadaten-Header (Schweregrad, Plattformen, MITRE-IDs, CVEs, detections.ai-Link). Importieren Sie direkt in Sentinel als geplante Abfrageregel oder in Defender XDR als benutzerdefinierte Erkennung.
Regeln sind auch in Splunk SPL, Elastic, Chronicle und anderen Stacks über die Sprachübersetzungsfunktion von detections.ai verfügbar.
Ethan Andrews Vertrauenswürdiger Mitwirkender — detections.ai
| Ordner | Verfolgte Dateien |
|---|
| objdump-dlx-calc-poc | 41 |
| ghidra-12.1.2-rce-ace-calc-poc | 9 |
| openvpn-connect-echo-script-ace-poc | 8 |
| lunar-modrinth-chain-poc | 6 |
| docker-cp-copyout-destination-escape | 5 |
| imagemagick-gs-delegate-hijack-poc | 5 |
| mybb-limited-acp-to-admin | 5 |
| nmap-ipv6-extlen-wrap-poc | 4 |
| anydesk-printer-com-impersonation-poc | 4 |
| gitea-act-runner-container-options-poc | 4 |
| 7zip-rar5-motw-chain-poc | 3 |
| flowise-mcp-env-case-bypass-poc | 3 |
| floci-apigateway-vtl-rce-poc | 3 |
| libssh2-cve-2026-55200-poc | 3 |
| vlc-vp9-reschange-crash-poc | 3 |
| Gesamt | 109 |
| Produkt | Regeln | CVEs |
|---|
| libssh2 | 7 | CVE-2026-55200, CVE-2026-55199 |
| Splunk | 4 | CVE-2026-20253 |
| RustDesk | 4 | CVE-2026-46331 |
| 7-Zip | 3 | CVE-2026-45115 |
| VLC | 3 | CVE-2026-20896 |
| AnyDesk | 3 | — |
| OpenVPN Connect | 3 | CVE-2026-45115 |
| c-ares | 3 | — |
| curl | 2 | — |
| libarchive | 2 | — |
| MyBB | 2 | — |
| PHP | 2 | — |
| Lunar Client | 2 | — |
| Next.js | 2 | — |
| NodeBB | 2 | — |
| Pillow | 2 | — |
| Exploitarium Generic | 2 | — |
| Docker | 1 | — |
| Firefox | 1 | — |
| Flowise | 1 | — |
| Ghidra | 1 | — |
| ImageMagick | 1 | — |
| Nmap | 1 | — |
| CVE | CVSS | Betroffen | Regeln |
|---|
| CVE-2026-55200 | 9.2 | libssh2 ≤1.1.1 (transitiv: curl, Git, PHP) | 5 |
| CVE-2026-55199 | — | libssh2-DoS durch CPU-Spin bei Schlüsselaustausch | 2 |
| CVE-2026-20253 | — | Splunk splunkd RCE | 4 |
| CVE-2026-46331 | — | RustDesk-Sitzungsberechtigungsumgehung | 4 |
| CVE-2026-45115 | — | 7-Zip MOTW-Bypass + OpenVPN ACE | 4 |
| CVE-2026-20896 | — | VLC VP9-Heap-Korruption | 3 |
| Plattform | Regeln |
|---|
| Windows | 38 |
| Linux | 25 |
| macOS | 6 |
| Container/Laufzeit | 3 |
| Netzwerk (NDR/CSL) | 1 |
| SaaS | 1 |
| # | Ordner | Datei | CVE |
|---|
| 01 | libssh2 | cve-2026-55200-pre-auth-rce-child-process.kql | CVE-2026-55200 |
| 02 | 7zip | 7zip-rar5-motw-bypass-extracted-exe-launch.kql | CVE-2026-45115 |
| 03 | rustdesk | rustdesk-session-permission-bypass-comprehensive.kql | CVE-2026-46331 |
| 04 | vlc | vlc-vp9-resolution-change-crash-child-spawn.kql | CVE-2026-20896 |
| 05 | mybb | mybb-acp-privesc-limited-admin-template-plugin.kql | — |
| 06 | anydesk | anydesk-printer-com-hijack-dll-load.kql | — |
| 07 | c-ares | c-ares-tcp-uaf-dns-formerr-rst-ndr.kql | — |
| 08 | c-ares | c-ares-linkage-discovery-ldd-readelf-recon.kql | — |
| 09 | firefox | firefox-smartwindow-silent-enable-attacker-endpoint.kql | — |
| 10 | php | php-857-soap-rce-heap-spray.kql | — |
| 11 | php | php-aslr-defeat-proc-self-maps-mem.kql | — |
| 12 | libssh2 | cve-2026-55200-malicious-ssh-scaffold-cipher-negotiation.kql | CVE-2026-55200 |
| 13 | libssh2 | cve-2026-55200-libpwn-scaffold-execution.kql | CVE-2026-55200 |
| 14 | openvpn | openvpn-pac-autoconfigurl-injection.kql | — |
| 15 | lunar-client | lunar-client-electron-preload-ipc-privesc.kql | — |
| 16 | lunar-client | lunar-client-modrinth-ipc-gamedirectory-abuse.kql | — |
| 17 | anydesk | anydesk-976-pe-fingerprint-recon.kql | — |
| 18 | nmap | nmap-ipv6-extlen-wrap-poc-compilation-execution.kql | — |
| 19 | rustdesk | rustdesk-anomalous-relay-connection-ports.kql | CVE-2026-46331 |
| 20 | splunk | cve-2026-20253-splunkd-unexpected-child-process.kql | CVE-2026-20253 |
| 21 | mybb | mybb-limited-acp-accessing-superadmin-functions.kql | — |
| 22 | exploitarium-generic | exploitarium-poc-calc-spawned-by-anomalous-parent.kql | — |
| 23 | rustdesk | rustdesk-session-permission-bypass-comprehensive.kql | CVE-2026-46331 |
| 24 | libssh2 | libssh2-linkage-recon-ldd-readelf-strings.kql | CVE-2026-55200 |
| 25 | libssh2 | cve-2026-55199-libssh2-dos-cpu-spin.kql | CVE-2026-55199 |
| 26 | libssh2 | libssh2-publickey-heap-corruption-poc.kql | CVE-2026-55200 |
| 27 | 7zip | cve-2026-45115-7zip-motw-archive-extraction-temp-execution.kql | CVE-2026-45115 |
| 28 | 7zip | cve-2026-45115-7zip-rar5-motw-zone-identifier-absent.kql | CVE-2026-45115 |
| 29 | vlc | cve-2026-20896-vlc-vp9-crash-dump-wer-report.kql | CVE-2026-20896 |
| 30 | vlc | cve-2026-20896-vlc-suspicious-child-process-vp9-decode.kql | CVE-2026-20896 |
| 31 | splunk | cve-2026-20253-splunk-rce-reverse-shell-indicators.kql | CVE-2026-20253 |
| 32 | splunk | cve-2026-20253-splunk-malicious-search-command-rest-api.kql | CVE-2026-20253 |
| 33 | rustdesk | cve-2026-46331-rustdesk-unauthenticated-relay-forged-token.kql | CVE-2026-46331 |
| 34 | rustdesk | cve-2026-46331-rustdesk-relay-server-impersonation-nonstandard-port.kql | CVE-2026-46331 |
| 35 | libssh2 | cve-2026-55199-libssh2-dos-malformed-kex-init-flood.kql | CVE-2026-55199 |
| 36 | anydesk | anydesk-com-printer-pipe-named-pipe-creation.kql | — |
| 37 | flowise | flowise-ai-server-unauthorized-api-access-prompt-injection.kql | — |
| 38 | docker | docker-container-escape-privileged-host-mount-shell.kql | — |
| 39 | imagemagick | imagemagick-policy-bypass-delegate-execution.kql | — |
| 40 | ghidra | ghidra-headless-analyzer-suspicious-script-execution.kql | — |
| 41 | c-ares | c-ares-tcp-uaf-dns-resolution-failure-spike.kql | — |
| 42 | openvpn | openvpn-dhcp-option-injection-autoconfigurl-registry.kql | — |
| 43 | splunk | cve-2026-20253-splunk-exploit-poc-script-artifact.kql | CVE-2026-20253 |
| 44 | exploitarium-generic | multi-cve-exploitarium-sweep-simultaneous-poc.kql | Alle 6 CVEs |
| 45 | curl | curl-smtp-expn-crlf-injection-attempt.kql | — |
| 46 | curl | curl-smtp-expn-crlf-poc-artifact-detection.kql | — |
| 47 | nodebb | nodebb-activitypub-uid-spoof-poc-execution.kql | — |
| 48 | nodebb | nodebb-activitypub-attributedto-uid-spoof-outbound-actor-fetch.kql | — |
| 49 | nextjs | nextjs-unstable-cache-poc-execution.kql | — |
| 50 | nextjs | nextjs-unstable-cache-object-argument-collision-cache-poisoning.kql | — |
| 51 | libarchive | libarchive-zip-debuginfod-size-boundary-poc-execution.kql | — |
| 52 | libarchive | libarchive-debuginfod-zip-size-boundary-bypass-poc.kql | — |
| 53 | pillow | pillow-imagecms-oob-write-poc-execution.kql | — |
| 54 | pillow | pillow-imagecms-oob-write-crash-detection.kql | — |