Possible path traversal via HTTP request
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
2 Days
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent
Detector Tags
Webshell Analytics
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
File and Directory Discovery (T1083)
Severity
Low
Description
The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt.
Attacker's Goals
Attackers may exploit server components or misconfigurations to access arbitrary sensitive files on the web server.
Investigative actions
Inspect the legitimacy of the URI path.
Ensure that the rare URI is not a legitimate result of routine development actions on the web server.
Variations
PreviousPossible Password Spray in universal authentication
NextPossible Persistence via group policy Registry keys
Was this helpful?
