Techniques
Sample rules
Potential NetScaler Log Poisoning Command Injection Attempt
- source: elastic
- technicques:
- T1059
- T1190
Description
Detects shell syntax in NetScaler Pitboss records or in Citrix records that combine Pitboss, packet-engine, or core terminology with shell syntax. This may indicate that attacker-controlled data poisoned an appliance log consumed by a privileged script. The behavior includes CVE-2026-88771, but the detection is intended to identify similar NetScaler log-poisoning command-injection attempts without requiring a specific vulnerability, failure phrase, or command.
Detection logic
any where
data_stream.dataset == "citrix_adc.log" and
(
(
citrix.detail regex~ """.*pitboss.*(nsppe|ppe|packet.*engine|core).*""" and
citrix.detail like~ (
"*;*", "*`*", "*$(*", "*&&*", "*||*",
"*%3b*", "*%60*", "*%7c*", "*%24%28*", "*%26%26*", "*%3e*", "*%3c*"
)
) or
(
citrix.device_event_class_id == "PITBOSS" and
citrix_adc.log.message like~ (
"*;*", "*`*", "*$(*", "*|*", "*>*", "*<*", "*&&*", "*||*",
"*%3b*", "*%60*", "*%7c*", "*%24%28*", "*%26%26*", "*%3e*", "*%3c*"
)
)
)