OpenCanary: HTTP Form POST Login Attempt Observed on Port Service

Alerts on OpenCanary HTTP Form POST events indicating a login attempt to an exposed service.

FreeReviewedSigma · High · v5
Product
opencanary
Category
application
Author
Security Onion Solutions (SigmaHQ), DRL 1.1
Published
2024-03-08
Updated
2026-07-31
title: "OpenCanary: HTTP Form POST Login Attempt Observed on Port Service"
id: 886245f3-5576-4828-9de0-b0fb67942c3b
status: test
description: This rule flags OpenCanary events where an HTTP service on an OpenCanary node records a login attempt sent via an HTTP POST using a form-based request. Login attempts over POST are a common initial step in credential guessing and automated probing against exposed web services. It relies on OpenCanary application logs indicating a form POST login attempt (logtype 3001).
references:
  - https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
  - https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_http_post_login_attempt.yml
author: Security Onion Solutions, Huntrule Team
date: 2024-03-08
tags:
  - attack.initial-access
  - attack.t1190
logsource:
  category: application
  product: opencanary
detection:
  selection:
    logtype: 3001
  condition: selection
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: af1ac430-df6b-4b38-b976-0b52f07a0252
    type: derived