Analytics BIOC Low

Possible path traversal via HTTP request

The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall EAL Logs, XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: File and Directory Discovery (T1083)
Detector tags: Webshell Analytics
Attacker's goals:

Attackers may exploit server components or misconfigurations to access arbitrary sensitive files on the web server.

Investigative actions:

Inspect the legitimacy of the URI path. Ensure that the rare URI is not a legitimate result of routine development actions on the web server.

Test period:
N/A (single event)
Deduplication:
2 Days
3 variations:
  • Possible sensitive path traversal via HTTP request Medium (parent: Low)
  • Possible path traversal via HTTP request from a TOR exit node Medium (parent: Low)
  • Possible credential path traversal via HTTP request Medium (parent: Low)