Proxy WebDAV MiniRedir Drives Execution from External Shares

Alert on external WebDAV MiniRedir GET requests for executable-like file extensions that may lead to execution.

FreeReviewedSigma · High · v2
Category
proxy
Author
Ahmed Farouk (SigmaHQ), DRL 1.1
Published
2024-05-10
Updated
2026-07-31

ATT&CK techniques

Resource Dev → Initial Access
  1. Recon

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags proxy requests where the client uses the WebDAV Explorer mini redirect user agent and issues GET requests to WebDAV URLs that end in executable or script archive extensions (e.g., .exe, .bat, .ps1, .zip, .lnk). Attackers often leverage WebDAV to stage and deliver payloads during initial access or follow-on execution attempts, so identifying these download patterns helps detect malicious delivery. It relies on proxy telemetry fields for the HTTP user agent, method, and full request URI, and filters out common local destination IP ranges.

Related detections9 linkedT1566 — drag to rearrange
Windows WebDAV Temporary File Creation with Suspicious Extensions
Malicious Office 365 Email Rule Breach - On Behalf (via office365)
Suspicious AWS Console AiTM Phishing Kit API Endpoints
Suspicious PowerShell Download of updserc Archive to AppData via ClickFix
AWS CloudTrail SSM SendCommand Successful Execution for Instance
Okta FastPass blocks phishing authentication attempts via MFA
macOS Script Editor Spawns Suspicious Command-Line Interpreters
Suspicious Process Execution by Microsoft OneNote on Windows Child Programs
Windows DLL Search Order Hijacking: Suspicious DLL Writes to App Dependency Folders
Proxy WebDAV MiniRedir Drives Execution from External Shares
Pivot detection · T1566 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.