This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Suspicious External WebDAV Execution
Original Source:
[Sigma source]
Title:
Suspicious External WebDAV Execution
Status:
test
Description:
Detects executables launched from external WebDAV shares using the WebDAV Explorer integration, commonly seen in initial access campaigns.
References:
-https://dear-territory-023.notion.site/WebDav-Share-Testing-e4950fa0c00149c3aa430d779b9b1d0f?pvs=4
-https://micahbabinski.medium.com/search-ms-webdav-and-chill-99c5b23ac462
-https://www.trendmicro.com/en_no/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html
-https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html
Author:
Ahmed Farouk
Date:
2024-05-10
modified:
None
Tags:
-'attack.initial-access'
-'attack.resource-development'
-'attack.t1584'
-'attack.t1566'
Logsource:
category: proxy
Detection:
selection_webdav:
c-useragent|startswith
:
'Microsoft-WebDAV-MiniRedir/'
cs-method
:
'GET'
selection_execution:
c-uri|endswith
:
-'.7z'
-'.bat'
-'.dat'
-'.cmd'
-'.exe'
-'.js'
-'.lnk'
-'.ps1'
-'.rar'
-'.url'
-'.vbe'
-'.vbs'
-'.zip'
filter_main_local_ips:
dst_ip|cidr
:
-'127.0.0.0/8'
-'10.0.0.0/8'
-'172.16.0.0/12'
-'192.168.0.0/16'
-'169.254.0.0/16'
-'::1/128'
-'fe80::/10'
-'fc00::/7'
condition
:
all of selection_* and not 1 of filter_main_*
Falsepositives:
-Unknown
Level:
high