{"id":"550d3350-bb8a-4ff3-9533-2ba533f4a1c0","title":"ProxyLogon MSExchange OabVirtualDirectory","description":"Detects specific patterns found after a successful ProxyLogon exploitation in relation to a Commandlet invocation of Set-OabVirtualDirectory","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-08-09","modified":"2023-01-23","tags":["attack.t1587.001","attack.resource-development"],"technique_ids":["T1587.001"],"logsource":{"product":"windows","service":"msexchange-management"},"falsepositives":["Unlikely"],"references":["https://bi-zone.medium.com/hunting-down-ms-exchange-attacks-part-1-proxylogon-cve-2021-26855-26858-27065-26857-6e885c5f197c"],"source_path":"rules/windows/builtin/msexchange/win_exchange_proxylogon_oabvirtualdir.yml","source_sha256":"9705b2f3f28a85e9c3d4d97ac4022c686de433e040ee3151b0c9ec61e7b5cbf3","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/msexchange/win_exchange_proxylogon_oabvirtualdir.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: ProxyLogon MSExchange OabVirtualDirectory\nid: 550d3350-bb8a-4ff3-9533-2ba533f4a1c0\nstatus: test\ndescription: Detects specific patterns found after a successful ProxyLogon exploitation in relation to a Commandlet invocation of Set-OabVirtualDirectory\nreferences:\n    - https://bi-zone.medium.com/hunting-down-ms-exchange-attacks-part-1-proxylogon-cve-2021-26855-26858-27065-26857-6e885c5f197c\nauthor: Florian Roth (Nextron Systems)\ndate: 2021-08-09\nmodified: 2023-01-23\ntags:\n    - attack.t1587.001\n    - attack.resource-development\nlogsource:\n    product: windows\n    service: msexchange-management\ndetection:\n    keywords_cmdlet:\n        '|all':\n            - 'OabVirtualDirectory'\n            - ' -ExternalUrl '\n    keywords_params:\n        - 'eval(request'\n        - 'http://f/<script'\n        - '\"unsafe\"};'\n        - 'function Page_Load()'\n    condition: keywords_cmdlet and keywords_params\nfalsepositives:\n    - Unlikely\nlevel: critical\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1587.001","id":"T1587.001","name":"Malware","page":"techniques/enterprise/T1587.001/"}],"data_path":"data/detection-rules/550d3350-bb8a-4ff3-9533-2ba533f4a1c0.json","kind":"sigma"}
