Suspicious Palo Alto GlobalProtect Session Unmarshal Path Traversal and Command Injection Attempts

Detects GlobalProtect logs with directory traversal/command injection-style indicators tied to CVE-2024-3400 behavior.

FreeReviewedSigma · High · v5
Product
paloalto
Category
appliance
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-04-18
Updated
2026-07-31

What it detects

This rule flags potential exploitation activity against Palo Alto GlobalProtect by matching telemetry indicative of directory traversal or OS command injection behavior. It looks for log entries containing specific failed-unmarshal session patterns that include traversal sequences, as well as combinations of command-leaning strings (e.g., base64, bash, curl, http, {IFS}) occurring within the GlobalProtect device telemetry temporary path. The detection relies on ingested GlobalProtect appliance logs (including mp-log and gpsvc.log) that contain the matched string patterns.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.