Skip to content

Hide Navigation Hide TOC

Suspicious Windows Strings In URI (9f6a34b4-2688-4eb7-a7f5-e39fef573d0e)

Detects suspicious Windows strings in URI which could indicate possible exfiltration or webshell communication

Cluster A Galaxy A Cluster B Galaxy B Level
Web Shell - T1505.003 (5d0d3609-d06d-49e1-b9c9-b544e0c618cb) Attack Pattern Suspicious Windows Strings In URI (9f6a34b4-2688-4eb7-a7f5-e39fef573d0e) Sigma-Rules 1
Web Shell - T1505.003 (5d0d3609-d06d-49e1-b9c9-b544e0c618cb) Attack Pattern Server Software Component - T1505 (d456de47-a16f-4e46-8980-e67478a12dcb) Attack Pattern 2