Detects Suspicious POST Requests Targeting Microsoft Exchange OWA/ECP Paths

Flags POST traffic to Exchange OWA/ECP-related URLs with specific client and user-agent indicators consistent with exploitation attempts.

FreeUnreviewedSigmahighv1
title: Detects Suspicious POST Requests Targeting Microsoft Exchange OWA/ECP Paths
id: 11797fde-9c4f-4bf7-a3f0-1795dc7d9432
status: test
description: This rule identifies potential exploitation activity by flagging HTTP POST requests whose URL paths and user agents match patterns associated with Exchange OWA and ECP components. Attackers often use scripted requests or custom clients to probe and exploit exposed Exchange endpoints, so correlating these requests in webserver logs can help surface initial access attempts. It relies on telemetry fields for HTTP method, request URI query/contents, and user-agent strings as recorded by the webserver logs.
references:
  - https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
  - https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/HAFNIUM/web_exchange_exploitation_hafnium.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-03-03
modified: 2023-01-02
tags:
  - attack.initial-access
  - attack.t1190
  - attack.g0125
  - detection.emerging-threats
logsource:
  category: webserver
detection:
  selection_1:
    cs-method: POST
    cs-uri-query|contains: /owa/auth/Current/themes/resources/
  selection_2:
    cs-method: POST
    cs-uri-query|contains: /owa/auth/Current/
    cs-user-agent:
      - DuckDuckBot/1.0;+(+http://duckduckgo.com/duckduckbot.html)
      - facebookexternalhit/1.1+(+http://www.facebook.com/externalhit_uatext.php)
      - Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html)
      - Mozilla/5.0+(compatible;+Bingbot/2.0;++http://www.bing.com/bingbot.htm)
      - Mozilla/5.0+(compatible;+Googlebot/2.1;++http://www.google.com/bot.html
      - Mozilla/5.0+(compatible;+Konqueror/3.5;+Linux)+KHTML/3.5.5+(like+Gecko)+(Exabot-Thumbnails)
      - Mozilla/5.0+(compatible;+Yahoo!+Slurp;+http://help.yahoo.com/help/us/ysearch/slurp)
      - Mozilla/5.0+(compatible;+YandexBot/3.0;++http://yandex.com/bots)
      - Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36
  selection_3:
    cs-uri-query|contains: /ecp/
    cs-method: POST
    cs-user-agent:
      - ExchangeServicesClient/0.0.0.0
      - python-requests/2.19.1
      - python-requests/2.25.1
  selection_4:
    cs-uri-query|contains:
      - /aspnet_client/
      - /owa/
    cs-method: POST
    cs-user-agent:
      - antSword/v2.1
      - Googlebot/2.1+(+http://www.googlebot.com/bot.html)
      - Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html)
  selection_5:
    cs-uri-query|contains:
      - /owa/auth/Current/
      - /ecp/default.flt
      - /ecp/main.css
    cs-method: POST
  selection_6:
    cs-method: POST
    cs-uri-query|contains|all:
      - /ecp/
      - .js
  condition: 1 of selection_*
falsepositives:
  - Legitimate access to other web applications that use the same folder names as Exchange (e.g. owa, ecp) but are not Microsoft Exchange related
level: high
license: DRL-1.1
related:
  - id: 67bce556-312f-4c81-9162-c3c9ff2599b2
    type: derived

What it detects

This rule identifies potential exploitation activity by flagging HTTP POST requests whose URL paths and user agents match patterns associated with Exchange OWA and ECP components. Attackers often use scripted requests or custom clients to probe and exploit exposed Exchange endpoints, so correlating these requests in webserver logs can help surface initial access attempts. It relies on telemetry fields for HTTP method, request URI query/contents, and user-agent strings as recorded by the webserver logs.

Known false positives

  • Legitimate access to other web applications that use the same folder names as Exchange (e.g. owa, ecp) but are not Microsoft Exchange related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.