OWA SSRF Exploitation Attempt via Proxy to /owa/mastermailbox and /powershell

Identifies proxy POSTs that return 200 and request both /owa/mastermailbox and /powershell, indicating potential OWASSRF exploitation.

FreeUnreviewedSigmacriticalv1
title: OWA SSRF Exploitation Attempt via Proxy to /owa/mastermailbox and /powershell
id: 2f5df738-7ed1-469d-bf27-269e00b142cb
status: test
description: This rule flags proxy traffic where a POST request returns HTTP 200 and the requested URI contains both /owa/mastermailbox and /powershell, consistent with an attempted SSRF chain targeting Exchange components. Attackers may use this pattern to reach PowerShell endpoints through the OWA front end. The detection relies on proxy logs capturing the user-agent, HTTP method, status code, and the requested URI path components.
references:
  - https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/
  - https://www.rapid7.com/blog/post/2022/12/21/cve-2022-41080-cve-2022-41082-rapid7-observed-exploitation-of-owassrf-in-exchange-for-rce/
  - https://twitter.com/purp1ew0lf/status/1602989967776808961?s=12&t=OkZJl_ViICeiftVEsohRyw
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2022/Exploits/CVE-2022-41082/proxy_cve_2022_36804_exchange_owassrf_poc_exploitation.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-12-22
tags:
  - attack.initial-access
  - attack.t1190
  - detection.emerging-threats
logsource:
  category: proxy
detection:
  selection:
    c-useragent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.5195.54 Safari/537.36
    cs-method: POST
    sc-status: 200
    c-uri|contains|all:
      - /owa/mastermailbox
      - /powershell
  condition: selection
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: fdd7e904-7304-4616-a46a-e32f917c4be4
    type: derived

What it detects

This rule flags proxy traffic where a POST request returns HTTP 200 and the requested URI contains both /owa/mastermailbox and /powershell, consistent with an attempted SSRF chain targeting Exchange components. Attackers may use this pattern to reach PowerShell endpoints through the OWA front end. The detection relies on proxy logs capturing the user-agent, HTTP method, status code, and the requested URI path components.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.