Possible OWASSRF exploitation attempt via Exchange OWA backend (webserver)
Alerts on successful POST requests to OWA URLs containing PowerShell backend indicators and Exchange-like probe user agents.
FreeUnreviewedSigmahighv1
possible-owassrf-exploitation-attempt-via-exchange-owa-backend-webserver-181f49fa
title: Possible OWASSRF exploitation attempt via Exchange OWA backend (webserver)
id: bc7bd953-86ef-455d-ad9b-2efb203f54b0
status: test
description: This rule flags HTTP POST responses with status 200 where the request targets an OWA path and includes PowerShell backend references in the URL query. It looks for user-agent patterns consistent with OWA/Exchange backend probing and query components that include an at-sign ("@" or "%40"). Such activity can indicate an attacker attempting server-side request forgery to reach internal PowerShell endpoints through the Exchange web interface. Detection relies on webserver telemetry capturing request method, response status, full URI query, and user-agent strings.
references:
- https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/
- https://www.rapid7.com/blog/post/2022/12/21/cve-2022-41080-cve-2022-41082-rapid7-observed-exploitation-of-owassrf-in-exchange-for-rce/
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2022/Exploits/CVE-2022-41082/web_cve_2022_36804_exchange_owassrf_exploitation.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-12-22
modified: 2023-01-02
tags:
- attack.initial-access
- attack.t1190
- detection.emerging-threats
logsource:
category: webserver
detection:
selection:
cs-method: POST
sc-status: 200
cs-uri-query|contains|all:
- /owa/
- /powershell
cs-uri-query|contains:
- "@"
- "%40"
filter_main_ua:
cs-user-agent:
- ClientInfo
- Microsoft WinRM Client
- Exchange BackEnd Probes
condition: selection and not 1 of filter_main_*
falsepositives:
- Web vulnerability scanners
level: high
license: DRL-1.1
related:
- id: 181f49fa-0b21-4665-a98c-a57025ebb8c7
type: derived
What it detects
This rule flags HTTP POST responses with status 200 where the request targets an OWA path and includes PowerShell backend references in the URL query. It looks for user-agent patterns consistent with OWA/Exchange backend probing and query components that include an at-sign ("@" or "%40"). Such activity can indicate an attacker attempting server-side request forgery to reach internal PowerShell endpoints through the Exchange web interface. Detection relies on webserver telemetry capturing request method, response status, full URI query, and user-agent strings.
Known false positives
- Web vulnerability scanners
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.