Zeek HTTP POST to /wsman without Authorization — Possible OMIGOD unauthenticated RCE (CVE-2021-38647)

Alert on HTTP 200 POST /wsman with no Authorization header and a non-empty body in Zeek logs, consistent with OMIGOD unauthenticated RCE attempts.

FreeReviewedSigma · High · v5
Product
zeek
Service
http
Author
Nate Guagenti (neu5ron) (SigmaHQ), DRL 1.1
Published
2021-09-20
Updated
2026-07-31

ATT&CK techniques

Initial Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags Zeek-observed HTTP traffic where a POST request to /wsman returns HTTP 200 without an Authorization header and with a non-empty HTTP client request body. This pattern is consistent with unauthenticated exploitation attempts that can lead to remote command execution as root, so alerting helps catch successful attack attempts that may not otherwise be obvious from headers alone. Telemetry relies on Zeek HTTP logs for status code, URI, HTTP method, presence of the Authorization header, and request body length, and it expects investigators to validate the request body and surrounding endpoint activity during the request timeframe.

Related detections9 linkedT1190 — drag to rearrange
Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Malicious OMI Server Spawning Shell as Root via OMIGOD SCX Provider (via process_creation)
Windows Process Creation: Suspicious cmd.exe or PowerShell Child of WSUS (wsusservice.exe)
Windows Application Logs: Detect WSUS deserialization exploitation via InvalidCastException indicators
Windows Process Creation: CrushFTP spawning PowerShell, CMD, and scripting tool execution
Windows spoolsv.exe Child Process Execution Indicators
Windows Terminal Service Parent Process Spawn (svchost.exe termsvcs)
Apache thread assertion error in error.log
Suspicious Child Process Spawned by WinRAR via Process Creation
Zeek HTTP POST to /wsman without Authorization — Possible OMIGOD unauthenticated RCE (CVE-2021-38647)
Pivot detection · T1190 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.