Windows TeamCity Plugin Installed: endpointEndpointNoneversion:2
Detects the creation of a plugin zip file under the TeamCity data structure.
This indicates a new plugin has been installed and can potentially indicate attempts to gain code execution on the TeamCity server if the plugin installation was unexpected.
JetBrains TeamCity RCE Attempt: networkWeb ServerNoneversion:11
The following analytic detects attempts to exploit the CVE-2023-42793 vulnerability in JetBrains TeamCity On-Premises.
It identifies suspicious POST requests to /app/rest/users/id:1/tokens/RPC2, leveraging the Web datamodel to monitor specific URL patterns and HTTP methods.
This activity is significant as it may indicate an unauthenticated attacker attempting to gain administrative access via Remote Code Execution (RCE).
If confirmed malicious, this could allow the attacker to execute arbitrary code, potentially compromising the entire TeamCity environment and leading to further unauthorized access and data breaches.
Windows TeamCity Payload Execution from Temp Directory: endpointEndpointNoneversion:2
Detects the bundled TeamCity java executing a payload out of the temp directory.
This activity can be associated with a malicious plugin installed by metasploit for remote code execution.