Skip to content

Hide Navigation Hide TOC

SSRF File Scheme Local File Read - ATR-2026-01608 (aec8b176-96e1-5f28-9a98-a5ccbbdea036)

Detects SSRF attempts using the file:// URI scheme to read local filesystem files via an agent's HTTP-fetch or URL-retrieval tool. Unlike network-based SSRF, file:// scheme attacks directly read OS files such as /etc/passwd, /etc/shadow, SSH private keys, or application configuration files containing secrets. Many HTTP client libraries and agent tools support file:// URIs unless explicitly blocked. Also catches absolute path injection (/etc/passwd) as a direct file read vector in fetch-style tool arguments.

Cluster A Galaxy A Cluster B Galaxy B Level
SSRF File Scheme Local File Read - ATR-2026-01608 (aec8b176-96e1-5f28-9a98-a5ccbbdea036) Agent Threat Rules File and Directory Discovery - T1083 (7bc57495-ea59-4380-be31-a64af124ef18) Attack Pattern 1
SSRF File Scheme Local File Read - ATR-2026-01608 (aec8b176-96e1-5f28-9a98-a5ccbbdea036) Agent Threat Rules Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern 1