OWASSRF Exploitation Attempt Using Public POC - Webserver — Detection Rule

Detects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint

Read the full analysis on IntelFusions