Suspicious Windows Strings In URI

 Original Source: [Sigma source]
Title: Suspicious Windows Strings In URI
Status: test
Description:Detects suspicious Windows strings in URI which could indicate possible exfiltration or webshell communication
References:
  -https://thedfirreport.com/2022/06/06/will-the-real-msiexec-please-stand-up-exploit-leads-to-data-exfiltration/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-06
modified:2023-01-02
Tags:
  • -'attack.persistence'
  • -'attack.exfiltration'
  • -'attack.t1505.003'
Logsource:
  • category: webserver
Detection:
  selection:
    cs-uri-query|contains:
      -'=C:/Users'
      -'=C:/Program%20Files'
      -'=C:/Windows'
      -'=C%3A%5CUsers'
      -'=C%3A%5CProgram%20Files'
      -'=C%3A%5CWindows'

  condition:selection
Falsepositives:
  -Legitimate application and websites that use windows paths in their URL
Level: high