Potential OWASSRF Exploitation Attempt - Proxy
Description
Detects exploitation attempt of the OWASSRF variant targeting exchange servers It uses the OWA endpoint to access the powershell backend endpoint
Query · sigma
selection: cs-method: POST sc-status: 200 c-uri|contains|all: - /owa/ - /powershell c-uri|contains: - '@' - '%40' filter_main_ua: c-useragent: - ClientInfo - Microsoft WinRM Client - Exchange BackEnd Probes condition: selection and not 1 of filter_main_*
Known false positives
- Web vulnerability scanners