Proxy HTTP GET Pattern Matching /MSHTML_C7/ with IPv4 Query Parameters

Alerts on proxy HTTP GET requests to /MSHTML_C7/ with an IPv4-like query parameter pattern.

FreeReviewedSigma · Critical · v5
Category
proxy
Author
X__Junior (SigmaHQ), DRL 1.1
Published
2023-07-12
Updated
2026-07-31

What it detects

This rule flags proxy traffic where an HTTP GET request targets a URI containing /MSHTML_C7/ and includes a query string formatted like four dot-separated IPv4 octets. Such highly specific URI patterns can indicate attempted exploitation workflows that rely on malformed or targeted request parameters. Detection relies on proxy logs capturing the HTTP method and the full requested URI, including query strings.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.