ADSelfService Exploitation
Description
Detects suspicious access to URLs that was noticed in cases in which attackers exploitated the ADSelfService vulnerability CVE-2021-40539
Query · sigma
selection: cs-uri-query|contains: - /help/admin-guide/Reports/ReportGenerate.jsp - /ServletApi/../RestApi/LogonCustomization - /ServletApi/../RestAPI/Connection condition: selection
Known false positives
- Unknown