OWA SSRF Exploitation Attempt via Webserver POST to /owa/mastermailbox and /powershell

Flags webserver POSTs returning 200 that request both /owa/mastermailbox and /powershell, consistent with OWASSRF exploitation attempts.

FreeUnreviewedSigmacriticalv1
title: OWA SSRF Exploitation Attempt via Webserver POST to /owa/mastermailbox and /powershell
id: ee940385-b00d-462a-826b-450cb1922280
status: test
description: This rule identifies a likely OWASSRF exploitation attempt against Exchange web endpoints by matching webserver activity where a POST request returns HTTP 200 and targets both the /owa/mastermailbox and /powershell paths in the query. The behavior matters because chaining access to the PowerShell backend through the OWA endpoint can indicate an attempt to progress toward remote code execution. It relies on webserver telemetry including HTTP method, status code, user agent, and the requested URI query contents.
references:
  - https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/
  - https://www.rapid7.com/blog/post/2022/12/21/cve-2022-41080-cve-2022-41082-rapid7-observed-exploitation-of-owassrf-in-exchange-for-rce/
  - https://twitter.com/purp1ew0lf/status/1602989967776808961?s=12&t=OkZJl_ViICeiftVEsohRyw
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2022/Exploits/CVE-2022-41082/web_cve_2022_36804_exchange_owassrf_poc_exploitation.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-12-22
modified: 2023-01-02
tags:
  - attack.initial-access
  - attack.t1190
  - detection.emerging-threats
logsource:
  category: webserver
detection:
  selection:
    cs-user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.5195.54 Safari/537.36
    cs-method: POST
    sc-status: 200
    cs-uri-query|contains|all:
      - /owa/mastermailbox
      - /powershell
  condition: selection
falsepositives:
  - Unlikely
level: critical
license: DRL-1.1
related:
  - id: 92d78c63-5a5c-4c40-9b60-463810ffb082
    type: derived

What it detects

This rule identifies a likely OWASSRF exploitation attempt against Exchange web endpoints by matching webserver activity where a POST request returns HTTP 200 and targets both the /owa/mastermailbox and /powershell paths in the query. The behavior matters because chaining access to the PowerShell backend through the OWA endpoint can indicate an attempt to progress toward remote code execution. It relies on webserver telemetry including HTTP method, status code, user agent, and the requested URI query contents.

Known false positives

  • Unlikely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.