JVM Application Error Logs Indicating Possible XXE Parsing Failures
Alerts on JVM XML parsing exception messages in application error logs that may indicate attempted XXE exploitation.
FreeUnreviewedSigmahighv1
jvm-application-error-logs-indicating-possible-xxe-parsing-failures-c4e06896
title: JVM Application Error Logs Indicating Possible XXE Parsing Failures
id: c4be6445-b934-42cd-8f0a-6410a1052228
status: test
description: This rule flags JVM application error logs that contain XML parser exceptions commonly seen during failed XML processing (e.g., SAXParseException or DOMException). Attackers may trigger these failures by submitting XML inputs intended to exploit XML processing behavior, so repeated or unexpected parser exceptions can be a useful signal for investigation. Telemetry relies on application error log events that capture the exception type text at error level or above.
references:
- https://rules.sonarsource.com/java/RSPEC-2755
- https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing
- https://www.wix.engineering/post/threat-and-vulnerability-hunting-with-application-server-error-logs
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/jvm/java_xxe_exploitation_attempt.yml
author: Moti Harmats, Huntrule Team
date: 2023-02-11
tags:
- attack.initial-access
- attack.t1190
logsource:
category: application
product: jvm
definition: "Requirements: application error logs must be collected (with LOG_LEVEL=ERROR and above)"
detection:
keywords:
- SAXParseException
- DOMException
condition: keywords
falsepositives:
- If the application expects to work with XML there may be parsing issues that don't necessarily mean XXE.
level: high
license: DRL-1.1
related:
- id: c4e06896-e27c-4583-95ac-91ce2279345d
type: derived
What it detects
This rule flags JVM application error logs that contain XML parser exceptions commonly seen during failed XML processing (e.g., SAXParseException or DOMException). Attackers may trigger these failures by submitting XML inputs intended to exploit XML processing behavior, so repeated or unexpected parser exceptions can be a useful signal for investigation. Telemetry relies on application error log events that capture the exception type text at error level or above.
Known false positives
- If the application expects to work with XML there may be parsing issues that don't necessarily mean XXE.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.