Citrix NetScaler directory traversal attempts targeting /vpns/ portal scripts and config files

Flags suspicious NetScaler HTTP URIs containing traversal-style /vpns/ portal script or config file references.

FreeUnreviewedSigmacriticalv1
title: Citrix NetScaler directory traversal attempts targeting /vpns/ portal scripts and config files
id: 263c5ba3-be3e-477a-8525-219ab2e3317b
status: test
description: This rule identifies HTTP requests to Citrix NetScaler that look like path traversal or crafted URI attempts aimed at /vpns/ resources, including portal script paths ending in .pl and a specific smb.conf file. Attackers may use these requests to reach sensitive configuration files or execute/abuse web-accessible script endpoints exposed through traversal. The detection relies on webserver logs capturing the HTTP request URI query and matches specific /vpns/ path patterns and script-like resource paths.
references:
  - https://support.citrix.com/article/CTX267679
  - https://support.citrix.com/article/CTX267027
  - https://isc.sans.edu/diary/25686
  - https://twitter.com/mpgn_x64/status/1216787131210829826
  - https://github.com/x1sec/CVE-2019-19781/blob/25f7ab97275b2d41800bb3414dac8ca3a78af7e5/CVE-2019-19781-DFIR.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2019/Exploits/CVE-2019-19781/web_cve_2019_19781_citrix_exploit.yml
author: Arnim Rupp, Florian Roth, Huntrule Team
date: 2020-01-02
modified: 2023-01-02
tags:
  - attack.initial-access
  - attack.t1190
  - cve.2019-19781
  - detection.emerging-threats
logsource:
  category: webserver
  definition: Make sure that your Netscaler appliance logs all kinds of attacks (test with http://your-citrix-gw.net/robots.txt). The directory traversal with ../ might not be needed on certain cloud instances or for authenticated users, so we also check for direct paths. All scripts in portal/scripts are exploitable except logout.pl.
detection:
  selection_cs:
    - cs-uri-query|contains: /../vpns/
    - cs-uri-query|endswith: /vpns/cfg/smb.conf
  selection_csall:
    cs-uri-query|contains|all:
      - /vpns/portal/scripts/
      - .pl
  condition: 1 of selection_*
falsepositives:
  - Unknown
level: critical
license: DRL-1.1
related:
  - id: ac5a6409-8c89-44c2-8d64-668c29a2d756
    type: derived

What it detects

This rule identifies HTTP requests to Citrix NetScaler that look like path traversal or crafted URI attempts aimed at /vpns/ resources, including portal script paths ending in .pl and a specific smb.conf file. Attackers may use these requests to reach sensitive configuration files or execute/abuse web-accessible script endpoints exposed through traversal. The detection relies on webserver logs capturing the HTTP request URI query and matches specific /vpns/ path patterns and script-like resource paths.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.