
KQL検出ルール(Microsoft SentinelおよびDefender XDR向け)。bikini/exploitarium匿名開示を対象としています。これは、15以上の異なる脆弱性ターゲット、109以上の追跡ファイルにわたる個人研究アーカイブであり、2026年6月23日にベンダーへの通知なしで公開されました。
Microsoft SentinelおよびDefender XDR向けのKQL検出ルール。bikini/exploitarium匿名公開に対応したもので、109以上のファイルにわたる15以上の異なる脆弱性ターゲットを含む個人研究アーカイブ。2026年6月23日にベンダー通知なしで公開されました。
54ルール | 23製品フォルダ | KQL | 作者: Ethan Andrews (@eandrews)
最終更新日: 2026/7/1
インテルレポート: https://systemtwosecurity.com/share/inspiration/VNJMKFVM
「bikini」と名乗る匿名の研究者がexploitariumを公開しました。これは、15以上の異なる脆弱性ターゲット(15以上のフォルダに109以上のファイル)にわたる概念実証研究を含むGitHubリポジトリです。リポジトリは積極的に更新されており、研究者が作業を発表し続けるにつれて新しいエントリが追加されています。
範囲の明確化: リポジトリには15の個別の脆弱性研究ターゲットが含まれています。フォルダごとのファイル数は、個別のCVEではなく、個々のファイル(スクリプト、ペイロード、ヘルパー、README)を反映しています。研究者のREADMEには、これらは投稿時点では未報告であり、他の人にCVEを提出するよう明示的に促しています。
最も技術的に重要な発見(libssh2の事前認証ヒープ書き込みとGiteaのデフォルトDocker認証バイパス)は、独立してリスクが高く、実際に悪用が観察されていると確認されています。一部のエントリは、コミュニティによって影響の低いノイズとして却下されています。
| フォルダ | 追跡ファイル数 |
|---|---|
| objdump-dlx-calc-poc | 41 |
| ghidra-12.1.2-rce-ace-calc-poc | 9 |
| openvpn-connect-echo-script-ace-poc | 8 |
| lunar-modrinth-chain-poc | 6 |
| docker-cp-copyout-destination-escape | 5 |
| imagemagick-gs-delegate-hijack-poc | 5 |
| mybb-limited-acp-to-admin | 5 |
| nmap-ipv6-extlen-wrap-poc | 4 |
| anydesk-printer-com-impersonation-poc | 4 |
| gitea-act-runner-container-options-poc | 4 |
| 7zip-rar5-motw-chain-poc | 3 |
| flowise-mcp-env-case-bypass-poc | 3 |
| floci-apigateway-vtl-rce-poc | 3 |
| libssh2-cve-2026-55200-poc | 3 |
| vlc-vp9-reschange-crash-poc | 3 |
| 合計 | 109 |
Exploitarium-Detections/
├── 7zip/ # MOTW bypass x3 (rules 02, 27, 28)
├── anydesk/ # COM hijack DLL, named pipe, PE fingerprint recon (rules 06, 17, 36)
├── c-ares/ # TCP UAF NDR sequence, linkage recon, DNS failure spike (rules 07, 08, 41)
├── curl/ # SMTP CRLF injection attempt + PoC artifact (rules 45, 46)
├── docker/ # Privileged container host mount shell spawn (rule 38)
├── exploitarium-generic/ # calc.exe PoC generic, multi-CVE sweep (rules 22, 44)
├── ffmpeg/ # (reserved)
├── firefox/ # SmartWindow silent enablement (rule 09)
├── flowise/ # Unauthorized API access (rule 37)
├── ghidra/ # Headless analyzer suspicious script execution (rule 40)
├── imagemagick/ # Policy bypass delegate execution (rule 39)
├── libarchive/ # ZIP debuginfod size boundary bypass x2 (rules 51, 52)
├── libssh2/ # Pre-auth RCE, DoS x2, scaffold x2, heap corruption, recon (rules 01, 12, 13, 24, 25, 26, 35)
├── lunar-client/ # Electron IPC preload, Modrinth gameDirectory abuse (rules 15, 16)
├── mybb/ # ACP privilege escalation x2 (rules 05, 21)
├── nextjs/ # unstable_cache PoC execution, cache object collision (rules 49, 50)
├── nmap/ # IPv6 ExtLen wrap PoC (rule 18)
├── nodebb/ # ActivityPub UID spoof x2 (rules 47, 48)
├── openvpn/ # PAC injection, echo script ACE, DHCP option injection (rules 14, 42, CVE-2026-45115)
├── php/ # SOAP RCE, ASLR bypass (rules 10, 11)
├── pillow/ # ImageCms OOB write PoC execution + crash detection (rules 53, 54, 55)
├── rustdesk/ # Session bypass x4 (rules 03, 19, 23, 33, 34)
├── splunk/ # splunkd child process, reverse shell, REST API, PoC artifact (rules 20, 31, 32, 43)
└── vlc/ # VP9 crash/child spawn, WER report, VP9 decode child (rules 04, 29, 30)
| 製品 | ルール数 | CVE |
|---|---|---|
| libssh2 | 7 | CVE-2026-55200, CVE-2026-55199 |
| Splunk | 4 | CVE-2026-20253 |
| RustDesk | 4 | CVE-2026-46331 |
| 7-Zip | 3 | CVE-2026-45115 |
| VLC | 3 | CVE-2026-20896 |
| AnyDesk | 3 | — |
| OpenVPN Connect | 3 | CVE-2026-45115 |
| c-ares | 3 | — |
| curl | 2 | — |
| libarchive | 2 | — |
| MyBB | 2 | — |
| PHP | 2 | — |
| Lunar Client | 2 | — |
| Next.js | 2 | — |
| NodeBB | 2 | — |
| Pillow | 2 | — |
| Exploitarium Generic | 2 | — |
| Docker | 1 | — |
| Firefox | 1 | — |
| Flowise | 1 | — |
| Ghidra | 1 | — |
| ImageMagick | 1 | — |
| Nmap | 1 | — |
| CVE | CVSS | 影響を受ける製品 | ルール数 |
|---|---|---|---|
| CVE-2026-55200 | 9.2 | libssh2 ≤1.1.1 (推移的: curl, Git, PHP) | 5 |
| CVE-2026-55199 | — | libssh2 DoS (鍵交換によるCPUスピン) | 2 |
| CVE-2026-20253 | — | Splunk splunkd RCE | 4 |
| CVE-2026-46331 | — | RustDesk セッション権限バイパス | 4 |
| CVE-2026-45115 | — | 7-Zip MOTWバイパス + OpenVPN ACE | 4 |
| CVE-2026-20896 | — | VLC VP9 ヒープ破損 | 3 |
| プラットフォーム | ルール数 |
|---|---|
| Windows | 38 |
| Linux | 25 |
| macOS | 6 |
| コンテナ/ランタイム | 3 |
| ネットワーク (NDR/CSL) | 1 |
| SaaS | 1 |
libssh2/cve-2026-55200-pre-auth-rce-child-process.kql — CVSS 9.2、実際に悪用ありlibssh2/libssh2-linkage-recon-ldd-readelf-strings.kql — 悪用前の偵察を捕捉libssh2/cve-2026-55200-libpwn-harness-binaries-endpoint.kql — エンドポイント上のハーネスバイナリexploitarium-generic/multi-cve-exploitarium-sweep-simultaneous-poc.kql — 最も広範囲なスイープsplunk/cve-2026-20253-splunkd-unexpected-child-process.kql — 価値の高いエンタープライズターゲットrustdesk/rustdesk-session-permission-bypass-comprehensive.kql — 完全なマルチブランチカバレッジcurl/curl-smtp-expn-crlf-injection-attempt.kql — libcurlを使用するメール送信SaaSに関連