Name:HTTP Rapid POST with Mixed Status Codes id:c8c987d6-3a1a-4555-9a52-eea0741b6113 version:5 date:None author:Raven Tait, Splunk status:production type:Anomaly Description:This detection identifies rapid-fire POST request attacks where an attacker sends more than 20 POST requests within a 5-second window, potentially attempting to exploit race conditions or overwhelm request handling. The pattern is particularly suspicious when responses vary in size or status codes, indicating successful exploitation attempts or probing for vulnerable endpoints. Data_source:
-Nginx Access
search:`nginx_access_logs` http_method="POST"
| bin _time span=5s
| rename dest_ip as dest
| stats count, values(status) as status_codes, values(bytes_out) as bytes_out, values(uri_path) as uris BY _time, src_ip, dest, http_user_agent
how_to_implement:This analytic necessitates the collection of web data, which can be achieved through Splunk Stream or by utilizing the Splunk Add-on for Apache Web Server. No additional configuration is required for this analytic. known_false_positives:False positives may be present if the activity is part of diagnostics or testing. Filter as needed. References: -https://portswigger.net/web-security/request-smuggling#what-is-http-request-smuggling -https://portswigger.net/research/http1-must-die -https://www.vaadata.com/blog/what-is-http-request-smuggling-exploitations-and-security-best-practices/ -https://www.securityweek.com/new-http-request-smuggling-attacks-impacted-cdns-major-orgs-millions-of-websites/ drilldown_searches: name:'View the detection results for - "$dest$"' search:'%original_detection_search% | search dest = "$dest$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$dest$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['HTTP Request Smuggling']