Microsoft Exchange exploitation attempt via suspicious POST requests in web server logs
Flags POST traffic to Exchange OWA/ECP-related URLs with specific client and user-agent indicators consistent with exploitation attempts.
- Category
- webserver
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2021-03-03
- Updated
- 2026-07-31
ATT&CK techniques
Initial AccessRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags HTTP POST activity against Microsoft Exchange-related paths (such as /owa/ and /ecp/) combined with specific user agents and query components. Attackers may use crafted requests to exploit exposed Exchange endpoints for initial access or remote exploitation. The detection relies on web server request telemetry, matching the HTTP method, URI query/content patterns, and exact or listed User-Agent strings.
Reporting behind it
- volexity.comhttps://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
- microsoft.comhttps://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/HAFNIUM/web_exchange_exploitation_hafnium.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Microsoft Exchange exploitation attempt via suspicious POST requests in web server logs
id: 11797fde-9c4f-4bf7-a3f0-1795dc7d9432
status: test
description: This rule flags HTTP POST activity against Microsoft Exchange-related paths (such as /owa/ and /ecp/) combined with specific user agents and query components. Attackers may use crafted requests to exploit exposed Exchange endpoints for initial access or remote exploitation. The detection relies on web server request telemetry, matching the HTTP method, URI query/content patterns, and exact or listed User-Agent strings.
references:
- https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
- https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/TA/HAFNIUM/web_exchange_exploitation_hafnium.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-03-03
modified: 2023-01-02
tags:
- attack.initial-access
- attack.t1190
- attack.g0125
- detection.emerging-threats
logsource:
category: webserver
detection:
selection_1:
cs-method: POST
cs-uri-query|contains: /owa/auth/Current/themes/resources/
selection_2:
cs-method: POST
cs-uri-query|contains: /owa/auth/Current/
cs-user-agent:
- DuckDuckBot/1.0;+(+http://duckduckgo.com/duckduckbot.html)
- facebookexternalhit/1.1+(+http://www.facebook.com/externalhit_uatext.php)
- Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html)
- Mozilla/5.0+(compatible;+Bingbot/2.0;++http://www.bing.com/bingbot.htm)
- Mozilla/5.0+(compatible;+Googlebot/2.1;++http://www.google.com/bot.html
- Mozilla/5.0+(compatible;+Konqueror/3.5;+Linux)+KHTML/3.5.5+(like+Gecko)+(Exabot-Thumbnails)
- Mozilla/5.0+(compatible;+Yahoo!+Slurp;+http://help.yahoo.com/help/us/ysearch/slurp)
- Mozilla/5.0+(compatible;+YandexBot/3.0;++http://yandex.com/bots)
- Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36
selection_3:
cs-uri-query|contains: /ecp/
cs-method: POST
cs-user-agent:
- ExchangeServicesClient/0.0.0.0
- python-requests/2.19.1
- python-requests/2.25.1
selection_4:
cs-uri-query|contains:
- /aspnet_client/
- /owa/
cs-method: POST
cs-user-agent:
- antSword/v2.1
- Googlebot/2.1+(+http://www.googlebot.com/bot.html)
- Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html)
selection_5:
cs-uri-query|contains:
- /owa/auth/Current/
- /ecp/default.flt
- /ecp/main.css
cs-method: POST
selection_6:
cs-method: POST
cs-uri-query|contains|all:
- /ecp/
- .js
condition: 1 of selection_*
falsepositives:
- Legitimate access to other web applications that use the same folder names as Exchange (e.g. owa, ecp) but are not Microsoft Exchange related
level: high
license: DRL-1.1
related:
- id: 67bce556-312f-4c81-9162-c3c9ff2599b2
type: derived