Generic detection rules FTW 🙌
The post-exploitation activity
@wiz_io showed yesterday makes these scripts light up like a Christmas tree🎄:
bash reverse shells, crypto miner indicators, history resets, wget/curl from http to bare IPs, base64 decoding, etc
If you keep your detection rules generic enough, they also cover tomorrow’s threats and post-exploitation activity of 0days that aren’t even discovered yet
WIZ report:
wiz.io/blog/nextjs-cve-2025-…