Name | No. Incidents | Techniques | Prevalence (%) | Nuclei | Metasploit | CISA KEV |
|---|---|---|---|---|---|---|
Adobe ColdFusion | ||||||
aiohttp | 1 | |||||
Amazon Bedrock | 1 | |||||
Amazon EKS | ||||||
Amazon SageMaker | 1 | |||||
Amazon SES | 1 | |||||
Amazon SNS | 0 | SNS abuse for spam or phishing | ||||
Ansible | 1 | |||||
Apache ActiveMQ | 6 | |||||
Apache Airflow | 0 | |||||
Apache Ant | 0 | |||||
Apache Axis | 0 | |||||
Apache Cassandra | 1 | |||||
Apache CloudStack | 0 | |||||
Apache CouchDB | 2 | |||||
Apache Druid | 1 | |||||
Apache Flink | 1 | |||||
Apache Hadoop | 7 | Misconfigured Apache Hadoop abuse | ||||
Apache HTTP Server | 3 | |||||
Apache Kafka | 0 | |||||
Apache OFBiz | ||||||
Apache RocketMQ | 1 | |||||
Apache Shiro | 0 | |||||
Apache Spark | 1 | |||||
Apache Struts | ||||||
Apache Subversion | 0 | |||||
Apache Superset | 0 | |||||
Apache Thrift | 0 | |||||
Apache Tomcat | 0 | |||||
Apache ZooKeeper | 0 | |||||
Apollo Server | 0 | |||||
Argo CD | 0 | Misconfigured Argo abuse | ||||
Aspera Faspex | 1 | |||||
Autodesk Revit | ||||||
Avahi | 0 | |||||
Aviatrix Controller | ||||||
AWS Amplify | 1 | |||||
AWS Appstream | 0 | Appstream abuse | ||||
AWS CloudFormation | 1 | Resource injection in CloudFormation template | ||||
AWS Codebuild | 1 | |||||
AWS ECS | 1 | |||||
AWS Fargate | 2 | |||||
AWS Lambda | 1 | Backdoor Lambda LayerServerless executionLambda persistence | ||||
AWS SSM | ||||||
Azure Arc | 0 | Azure Arc abuse | ||||
Azure Batch | 1 | Azure Batch abuse | ||||
Azure Entra ID | ||||||
Azure Storage | 3 | |||||
Barracuda ESG | 1 | |||||
BeyondTrust | ||||||
BitBucket Server | 1 | |||||
cAdvisor | cAdvisor abuse | |||||
CBL Mariner | 0 | |||||
Celery | 0 | |||||
Certbot | 0 | |||||
Chef Client | 0 | |||||
Chocolatey | 0 | |||||
Cisco Adaptive Security Appliance (ASA) | ||||||
Citrix NetScaler | ||||||
Citrix Receiver | 0 | |||||
Cleo file transfer software | ||||||
ClickHouse | 0 | |||||
CockroachDB | 0 | |||||
ComfyUI | ||||||
Confluence Server | 13 | |||||
ConnectWise ScreenConnect | 1 | |||||
containerd | 0 | |||||
CraftCMS | ||||||
Django | 0 | |||||
Docker | 16 | Abusing exposed Docker socketBackdoor Docker imageMisconfigured Docker abuse | ||||
DogWifTools | ||||||
Drupal | 1 | |||||
Elasticsearch | 3 | |||||
Envoy | 0 | |||||
ESXi Server | 1 | |||||
etcd | 0 | |||||
Exim | 1 | |||||
F5 BIG IP | 1 | |||||
FileZilla Server | 0 | |||||
Firebase | 0 | |||||
Flask | 0 | |||||
Flower | 0 | |||||
Fluent Bit | 0 | |||||
Flux Kustomize Controller | 0 | |||||
FortiClient | ||||||
Fortinet Fortigate | ||||||
Fortinet FortiManager | ||||||
FortiOS | ||||||
FRP Client | 0 | |||||
Geronimo | 0 | |||||
Ghostscript | 0 | |||||
Gitea | Misconfigured Gitea Abuse | |||||
gith | ||||||
GitHub | 6 | pwn requestRepository webhook abuseRegister self-hosted runnerScript injection into CICD workflow | ||||
GitLab | 3 | Script injection into CICD workflow | ||||
Google Cloud Storage | ||||||
Grafana | 0 | |||||
Gunicorn | 0 | |||||
H2 Database | 0 | |||||
HAProxy | 0 | |||||
Hashicorp Consul | 1 | Misconfigured Consul abuse | ||||
HashiCorp Vault | 0 | |||||
Helm | 0 | |||||
Hugging Face Transformers | 0 | |||||
ImageMagick | 0 | |||||
InfluxDB | 0 | |||||
InMage Scout | 0 | |||||
Istio | 0 | |||||
Ivanti Connect Secure VPN | 3 | |||||
Ivanti CSA | ||||||
Ivanti EPMM | ||||||
JDWP | ||||||
Jenkins | 6 | Repository webhook abuse | ||||
Jira Server | 3 | |||||
Jupyter Notebook | 4 | Jupyter Notebook misconfig abuseJupyter Notebook ransomware | ||||
JupyterLab | 1 | |||||
Keycloak | 0 | |||||
Kibana | 1 | |||||
Krpano | ||||||
KubeFlow | 0 | Misconfigured KubeFlow abuse | ||||
Kubernetes | 9 | Propagation via KubeletK8s anonymous auth abuse | ||||
LangChain | 0 | |||||
Langflow | ||||||
Laravel | 3 | |||||
LevelDB | 0 | |||||
Liferay | 1 | |||||
Lighttpd | ||||||
Linux | ||||||
Localtunnel | 0 | |||||
Lottie-player | ||||||
Magento | 1 | |||||
MariaDB | 0 | |||||
Maven | 0 | |||||
Mbed TLS | 0 | |||||
Memcached | 0 | |||||
Metabase | 1 | |||||
Metricbeat | 0 | |||||
Microsoft Exchange | 2 | Email server hijacking | ||||
Microsoft Graph API | ||||||
Microsoft IIS | 0 | |||||
Microsoft OneDrive | ||||||
Microsoft Outlook | ||||||
Microsoft Power Pages | Misconfigured Power Pages abuse | |||||
Microsoft SCCM | 0 | |||||
Microsoft SQL Server | 4 | SQL injectionSQL commands | ||||
Microsoft Teams | ||||||
Microsoft Word | ||||||
MinIO | 1 | |||||
Moby | 0 | |||||
MODX | 1 | |||||
MongoDB | 2 | |||||
Monit | 0 | |||||
MySQL | 1 | SQL injectionSQL commands | ||||
NGINX | 2 | |||||
ngrok | 0 | |||||
Nomad | ||||||
npm | 1 | Package dependency confusionSlopsquatting | ||||
Office365 | 1 | |||||
OMI | 0 | |||||
Open WebUI | ||||||
Openfire | ||||||
OpenMetadata | 1 | |||||
OpenResty | 0 | |||||
Openscap | 0 | |||||
OpenSearch | 0 | |||||
Oracle Cloud | ||||||
Oracle Database | 0 | |||||
Oracle E-Business Suite | ||||||
Packer | 0 | |||||
PAN-OS | 0 | |||||
PaperCut | 1 | |||||
PHP | 3 | |||||
phpMyAdmin | 1 | |||||
PHPUnit | ||||||
Podman | 0 | |||||
PostgreSQL | 4 | Misconfigured DB abuse | ||||
Prometheus | 0 | |||||
Proself | ||||||
Puppet | 0 | |||||
Puppet Agent | 0 | |||||
PyPI | SlopsquattingPackage dependency confusion | |||||
Qlink Sense | 1 | |||||
RabbitMQ | 0 | |||||
Redis | 13 | Redis-as-a-backdoorMisconfigured Redis abuse | ||||
ReportLab | 0 | |||||
RocksDB | 0 | |||||
RStudio | 0 | |||||
RubyGems | 0 | |||||
S3 Bucket | 5 | Storage Denial of Wallet amplification attack | ||||
Safe{wallet} | ||||||
Salesforce | 1 | |||||
Salesloft Drift | ||||||
SaltStack | 1 | |||||
Samba | 0 | |||||
SAP Crystal Reports | 0 | |||||
SAP NetWeaver | ||||||
ScienceLogic SL1 | ||||||
Selenium Grid | Misconfigured Selenium Grid abuse | |||||
SharePoint | 1 | |||||
SimpleHelp | ||||||
Slack | ||||||
Smartsheet | 1 | |||||
Snowflake | ||||||
Solana | ||||||
Solr | 1 | |||||
SonarQube | 0 | |||||
Sonatype Nexus | 0 | |||||
SonicWall firewall | ||||||
Splunk Forwarder | 0 | |||||
Spring Boot | 0 | Spring Boot Actuator abuse | ||||
Spring Boot Actuator | ||||||
Spring Cloud | 0 | |||||
Spring Framework | 1 | |||||
Squid | 0 | |||||
strongSwan | 0 | |||||
SugarCRM | 1 | |||||
Tableau Server | 0 | |||||
TaffyDB | 0 | |||||
Team Foundation Server | 0 | |||||
TeamCity | 2 | Repository webhook abuse | ||||
Telerik UI | ||||||
Tenable Nessus | 0 | |||||
Tensorflow Hub | 0 | |||||
TestNG | 0 | |||||
ThinkPHP | 1 | |||||
TigerVNC | 0 | |||||
TightVNC | 0 | |||||
TP-Link Router | ||||||
vCenter Server | 1 | |||||
Veeam | ||||||
Verdaccio | 0 | |||||
VirtualBox | 0 | |||||
Visual Studio Code | ||||||
VMware Horizon | 1 | |||||
VMware vSphere | ||||||
VMWare Workspace ONE Access and Identity Manager | ||||||
vsftpd | 0 | |||||
WebLogic | 3 | |||||
Windows AFD | ||||||
Windows Print Spooler | ||||||
Windows SmartScreen | ||||||
WinRAR | ||||||
WordPress | 3 | Misconfigured Wordpress abuse | ||||
WSO2 | 2 | |||||
Zabbix Agent | 0 | |||||
ZeroMQ | 0 | |||||
Zimbra Server | ||||||
Zoho ManageEngine | 1 | |||||
Zyxel |