Skip to content

Hide Navigation Hide TOC

SSRF Internal Network and Private IP Range Access - ATR-2026-01606 (a2881092-e895-58ad-ba62-17ae6f8b7640)

Detects SSRF attempts targeting RFC-1918 private IP ranges (192.168.x.x, 10.x.x.x, 172.16-31.x.x) and internal hostnames (e.g., internal.*, admin.internal). When an agent's HTTP-fetch tool follows a URL pointing to internal infrastructure, it may expose admin panels, internal APIs, microservice endpoints, or cloud-internal management planes that are not accessible from the public internet. Attackers use this to pivot from the agent into the internal network.

Cluster A Galaxy A Cluster B Galaxy B Level
SSRF Internal Network and Private IP Range Access - ATR-2026-01606 (a2881092-e895-58ad-ba62-17ae6f8b7640) Agent Threat Rules Proxy - T1090 (731f4f55-b6d0-41d1-a7a9-072a66389aea) Attack Pattern 1
SSRF Internal Network and Private IP Range Access - ATR-2026-01606 (a2881092-e895-58ad-ba62-17ae6f8b7640) Agent Threat Rules Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern 1