WebDav Put Request

 Original Source: [Sigma source]
Title: WebDav Put Request
Status: test
Description:A General detection for WebDav user-agent being used to PUT files on a WebDav network share. This could be an indicator of exfiltration.
References:
  -https://github.com/OTRF/detection-hackathon-apt29/issues/17
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
Date: 2020-05-02
modified:2024-03-13
Tags:
  • -'attack.exfiltration'
  • -'attack.t1048.003'
Logsource:
  • product: zeek
  • service: http
Detection:
  selection:
    user_agent|contains: 'WebDAV'
    method: 'PUT'
  filter:
    id.resp_h|cidr:
      -'10.0.0.0/8'
      -'127.0.0.0/8'
      -'172.16.0.0/12'
      -'192.168.0.0/16'
      -'169.254.0.0/16'

  condition:selection and not filter
Falsepositives:
  -Unknown
Level: low