Analytics BIOC
Medium
✕
Suspicious HTTP parameters detected
The endpoint received suspicious HTTP parameters via an HTTP request, which may indicate attempts to exploit server components or web shell activity.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall EAL Logs, XDR Agent
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003)
ATT&CK techniques: External Remote Services (T1133) Server Software Component: Web Shell (T1505.003)
Detector tags: Webshell Analytics
Attacker's goals:
Attackers may exploit server components or misconfigurations to access arbitrary sensitive files on the web server.
Investigative actions:
Inspect the legitimacy of the URI path and the parameters values sent to the server. Ensure that the rare URI is not a legitimate result of routine development actions on the web server.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day