
Summary
This rule detects potential NetScaler log poisoning via command injection by identifying shell syntax embedded in Pitboss records or in Citrix ADC logs that blend Pitboss, PPE, packet-engine, or core terminology with shell constructs. It targets attacker-controlled data written to appliance logs consumed by privileged scripts, which can precede or accompany exploitation such as CVE-2026-88771, but is designed to catch similar log-poisoning attempts even when a specific vulnerability signature is not present. The detection logic operates on the Elastic Citrix ADC integration data stream (citrix_adc.log) and checks two patterns: (1) in citrix.detail, the presence of pitboss/ppe/packet-engine/core terms together with shell tokens (e.g., ;, $, backticks, parentheses, pipes) or their percent-encoded variants; (2) in Citrix PITBOSS records (device_event_class_id == PITBOSS), where citrix_adc.log.message contains analogous shell tokens. A match indicates a potential poisoning attempt where attacker data could be interpreted by a privileged script. The rule maps to MITRE ATT&CK as Initial Access (T1190: Exploit Public-Facing Application) and Execution (T1059 with Unix Shell T1059.004) and is categorized under Network/Infrastructure-focused detection for Citrix ADC logs. Note that a match is not definitive proof of exploitation; it indicates suspicious content that warrants containment and thorough investigation.
Categories
- Network
- On-Premise
Data Sources
- Application Log
- File
ATT&CK Techniques
- T1190
- T1059
- T1059.004
Created: 2026-09-28