LoFP LoFP / splunk server

TitleTags
irregular path with files that may be purposely called for benign reasons may produce false positives.
none identified
only applies to affected versions of splunk enterprise below 9.2.1, 9.1.4, and 9.0.9
retrieving server information may be a legitimate api request. verify that the attempt is a valid request for information.
this is a hunting search and will produce false positives. operator must follow results into instances where curl requests coming from actual users may indicate intent of exploitation.
this search encompasses many commands.
this search is highly specific for vulnerable versions of splunk add-on builder. there are no known false positives.