Analytics BIOC Medium

Suspicious HTTP parameters detected

The endpoint received suspicious HTTP parameters via an HTTP request, which may indicate attempts to exploit server components or web shell activity.

Module:
Platform Analytics
Data source:
Palo Alto Networks Firewall EAL Logs, XDR Agent
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003)
ATT&CK techniques: External Remote Services (T1133) Server Software Component: Web Shell (T1505.003)
Detector tags: Webshell Analytics
Attacker's goals:

Attackers may exploit server components or misconfigurations to access arbitrary sensitive files on the web server.

Investigative actions:

Inspect the legitimacy of the URI path and the parameters values sent to the server. Ensure that the rare URI is not a legitimate result of routine development actions on the web server.

Test period:
N/A (single event)
Deduplication:
1 Day