Skip to content

Hide Navigation Hide TOC

SSRF Localhost Service Probe - ATR-2026-01607 (f971e3e8-29f4-501b-897a-c91c970311c2)

Detects SSRF attempts targeting localhost (127.0.0.1, ::1, 0.0.0.0) and common loopback aliases. Localhost-targeted SSRF probes services running on the agent's host that are bound only to the loopback interface: database admin interfaces (Redis 6379, MongoDB 27017, Elasticsearch 9200), internal API gateways, debug endpoints, or developer tooling. These services typically have no authentication because they assume only local access. Also catches IPv6 loopback (::1) and decimal/hex-encoded variants.

Cluster A Galaxy A Cluster B Galaxy B Level
SSRF Localhost Service Probe - ATR-2026-01607 (f971e3e8-29f4-501b-897a-c91c970311c2) Agent Threat Rules Cloud Instance Metadata API - T1552.005 (19bf235b-8620-4997-b5b4-94e0659ed7c3) Attack Pattern 1
SSRF Localhost Service Probe - ATR-2026-01607 (f971e3e8-29f4-501b-897a-c91c970311c2) Agent Threat Rules Craft Adversarial Data (a7c30122-b393-4265-91b7-57cd1211e3f9) MITRE ATLAS Attack Pattern 1
Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) Attack Pattern Cloud Instance Metadata API - T1552.005 (19bf235b-8620-4997-b5b4-94e0659ed7c3) Attack Pattern 2