Potential OWASSRF Exploitation via OWA Proxy Requests (HTTP 200) - Exchange

Alerts on 200-status proxy POSTs targeting OWA-to-PowerShell backend paths with encoded user info markers.

FreeReviewedSigma · High · v5
Category
proxy
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-12-22
Updated
2026-07-31
title: Potential OWASSRF Exploitation via OWA Proxy Requests (HTTP 200) - Exchange
id: 7e38801b-78f8-43e0-905b-32d69d27d6d1
status: test
description: This rule flags successful HTTP POST traffic where the request URI contains both OWA and the PowerShell backend path components, including encoded or literal '@' characters. Such requests may indicate an OWASSRF-style attempt to reach backend PowerShell functionality through the OWA proxy. It relies on proxy access log fields including HTTP method, status code, request URI, and client user-agent strings such as common Exchange probe or WinRM-related clients.
references:
  - https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/
  - https://www.rapid7.com/blog/post/2022/12/21/cve-2022-41080-cve-2022-41082-rapid7-observed-exploitation-of-owassrf-in-exchange-for-rce/
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2022/Exploits/CVE-2022-41082/proxy_cve_2022_36804_exchange_owassrf_exploitation.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-12-22
tags:
  - attack.initial-access
  - attack.t1190
  - detection.emerging-threats
logsource:
  category: proxy
detection:
  selection:
    cs-method: POST
    sc-status: 200
    c-uri|contains|all:
      - /owa/
      - /powershell
    c-uri|contains:
      - "@"
      - "%40"
  filter_main_ua:
    c-useragent:
      - ClientInfo
      - Microsoft WinRM Client
      - Exchange BackEnd Probes
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Web vulnerability scanners
level: high
license: DRL-1.1
related:
  - id: 1ddf4596-1908-43c9-add2-1d2c2fcc4797
    type: derived