HTTP GET Requests Containing /MSHTML_C7/ URL Marker (Proxy Logs)

Alerts on proxy HTTP GET requests whose URI contains /MSHTML_C7/.

FreeReviewedSigma · High · v5
Category
proxy
Author
X__Junior (SigmaHQ), DRL 1.1
Published
2023-07-12
Updated
2026-07-31

What it detects

This rule flags HTTP proxy traffic where the request method is GET and the requested URI contains the specific marker /MSHTML_C7/. Attackers often use consistent URL patterns as part of exploit delivery or follow-on command-and-control workflows, making this marker useful for identifying potential exploitation attempts. Detection relies on proxy telemetry capturing HTTP method and full request URI content.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.