OWA SSRF Exploitation Attempt via Webserver POST to /owa/mastermailbox and /powershell
Flags webserver POSTs returning 200 that request both /owa/mastermailbox and /powershell, consistent with OWASSRF exploitation attempts.
FreeUnreviewedSigmacriticalv1
owa-ssrf-exploitation-attempt-via-webserver-post-to-owa-mastermailbox-and-powers-92d78c63
title: OWA SSRF Exploitation Attempt via Webserver POST to /owa/mastermailbox and /powershell
id: ee940385-b00d-462a-826b-450cb1922280
status: test
description: This rule identifies a likely OWASSRF exploitation attempt against Exchange web endpoints by matching webserver activity where a POST request returns HTTP 200 and targets both the /owa/mastermailbox and /powershell paths in the query. The behavior matters because chaining access to the PowerShell backend through the OWA endpoint can indicate an attempt to progress toward remote code execution. It relies on webserver telemetry including HTTP method, status code, user agent, and the requested URI query contents.
references:
- https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/
- https://www.rapid7.com/blog/post/2022/12/21/cve-2022-41080-cve-2022-41082-rapid7-observed-exploitation-of-owassrf-in-exchange-for-rce/
- https://twitter.com/purp1ew0lf/status/1602989967776808961?s=12&t=OkZJl_ViICeiftVEsohRyw
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2022/Exploits/CVE-2022-41082/web_cve_2022_36804_exchange_owassrf_poc_exploitation.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-12-22
modified: 2023-01-02
tags:
- attack.initial-access
- attack.t1190
- detection.emerging-threats
logsource:
category: webserver
detection:
selection:
cs-user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.5195.54 Safari/537.36
cs-method: POST
sc-status: 200
cs-uri-query|contains|all:
- /owa/mastermailbox
- /powershell
condition: selection
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
related:
- id: 92d78c63-5a5c-4c40-9b60-463810ffb082
type: derived
What it detects
This rule identifies a likely OWASSRF exploitation attempt against Exchange web endpoints by matching webserver activity where a POST request returns HTTP 200 and targets both the /owa/mastermailbox and /powershell paths in the query. The behavior matters because chaining access to the PowerShell backend through the OWA endpoint can indicate an attempt to progress toward remote code execution. It relies on webserver telemetry including HTTP method, status code, user agent, and the requested URI query contents.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.