Potential OWASSRF Exploitation Attempt - Webserver
Description
Detects exploitation attempt of the OWASSRF variant targeting exchange servers It uses the OWA endpoint to access the powershell backend endpoint
Query · sigma
selection: cs-method: POST sc-status: 200 cs-uri-query|contains|all: - /owa/ - /powershell cs-uri-query|contains: - '@' - '%40' filter_main_ua: cs-user-agent: - ClientInfo - Microsoft WinRM Client - Exchange BackEnd Probes condition: selection and not 1 of filter_main_*
Known false positives
- Web vulnerability scanners