OpenCanary application telemetry: HTTP GET requests received by monitored service

Alerts when OpenCanary logs an HTTP GET request to a monitored service endpoint.

FreeReviewedSigma · High · v5
Product
opencanary
Category
application
Author
Security Onion Solutions (SigmaHQ), DRL 1.1
Published
2024-03-08
Updated
2026-07-31
title: "OpenCanary application telemetry: HTTP GET requests received by monitored service"
id: 5d8796a0-b4a2-4498-8bf5-ae7c2c6f1c8f
status: test
description: This rule flags events from an OpenCanary node where the monitored HTTP service received an HTTP GET request. GET traffic can indicate reconnaissance or attempts to access the service endpoint, even when no credentials are involved. The detection relies on OpenCanary application logs containing an event with the HTTP request log type value that corresponds to GET handling.
references:
  - https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
  - https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_http_get.yml
author: Security Onion Solutions, Huntrule Team
date: 2024-03-08
tags:
  - attack.initial-access
  - attack.t1190
logsource:
  category: application
  product: opencanary
detection:
  selection:
    logtype: 3000
  condition: selection
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: af6c3078-84cd-4c68-8842-08b76bd81b13
    type: derived