heroui logo

Potential NetScaler Log Poisoning Command Injection Attempt

Elastic Detection Rules

View Source
Summary
This rule detects potential NetScaler log poisoning via command injection by identifying shell syntax embedded in Pitboss records or in Citrix ADC logs that blend Pitboss, PPE, packet-engine, or core terminology with shell constructs. It targets attacker-controlled data written to appliance logs consumed by privileged scripts, which can precede or accompany exploitation such as CVE-2026-88771, but is designed to catch similar log-poisoning attempts even when a specific vulnerability signature is not present. The detection logic operates on the Elastic Citrix ADC integration data stream (citrix_adc.log) and checks two patterns: (1) in citrix.detail, the presence of pitboss/ppe/packet-engine/core terms together with shell tokens (e.g., ;, $, backticks, parentheses, pipes) or their percent-encoded variants; (2) in Citrix PITBOSS records (device_event_class_id == PITBOSS), where citrix_adc.log.message contains analogous shell tokens. A match indicates a potential poisoning attempt where attacker data could be interpreted by a privileged script. The rule maps to MITRE ATT&CK as Initial Access (T1190: Exploit Public-Facing Application) and Execution (T1059 with Unix Shell T1059.004) and is categorized under Network/Infrastructure-focused detection for Citrix ADC logs. Note that a match is not definitive proof of exploitation; it indicates suspicious content that warrants containment and thorough investigation.
Categories
  • Network
  • On-Premise
Data Sources
  • Application Log
  • File
ATT&CK Techniques
  • T1190
  • T1059
  • T1059.004
Created: 2026-09-28