Detecting RegreSSHion with Dynatrace (CVE-2024-6387)
Dynatrace
JULY 2, 2024
The Qualys Threat Research Unit (TRU) has discovered a Remote Unauthenticated Code Execution (RCE) vulnerability in OpenSSH server (sshd) in glibc-based Linux systems. Using the VPC flow log default pattern available in DPL Architect, we can extract the meaningful fields to see only the network traffic targeting the SSH port.
Let's personalize your content