Log source category
webserver log source Sigma rules
86 Sigma detection rules in the library use the webserver log source. The webserver category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Severity
Arcadyan Router Exploitations
criticalDetects exploitation of vulnerabilities in Arcadyan routers as reported in CVE-2021-20090 and CVE-2021-20091.
Citrix ADS Exploitation CVE-2020-8193 CVE-2020-8195
criticalDetects exploitation attempt against Citrix Netscaler, Application Delivery Controller (ADS) and Citrix Gateway exploiting vulnerabilities reported as CVE-2020-8193 and CVE-2020-8195
Citrix Netscaler Attack CVE-2019-19781
criticalDetects CVE-2019-19781 exploitation attempt against Citrix Netscaler, Application Delivery Controller and Citrix Gateway Attack
Confluence Exploitation CVE-2019-3398
criticalDetects the exploitation of the Confluence vulnerability described in CVE-2019-3398
CVE-2010-5278 Exploitation Attempt
criticalMODx manager - Local File Inclusion:Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter.
CVE-2020-0688 Exchange Exploitation via Web Log
criticalDetects the exploitation of Microsoft Exchange vulnerability as described in CVE-2020-0688
CVE-2020-10148 SolarWinds Orion API Auth Bypass
criticalDetects CVE-2020-10148 SolarWinds Orion API authentication bypass attempts
CVE-2020-5902 F5 BIG-IP Exploitation Attempt
criticalDetects the exploitation attempt of the vulnerability found in F5 BIG-IP and described in CVE-2020-5902
CVE-2021-33766 Exchange ProxyToken Exploitation
criticalDetects the exploitation of Microsoft Exchange ProxyToken vulnerability as described in CVE-2021-33766
CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
criticalDetects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).
CVE-2024-1709 - ScreenConnect Authentication Bypass Exploitation
criticalDetects GET requests to '/SetupWizard.aspx/[anythinghere]' that indicate exploitation of the ScreenConnect vulnerability CVE-2024-1709.
Exchange Exploitation CVE-2021-28480
criticalDetects successful exploitation of Exchange vulnerability as reported in CVE-2021-28480
Fortinet CVE-2018-13379 Exploitation
criticalDetects CVE-2018-13379 exploitation attempt against Fortinet SSL VPNs
Fortinet CVE-2021-22123 Exploitation
criticalDetects CVE-2021-22123 exploitation attempt against Fortinet WAFs
Grafana Path Traversal Exploitation CVE-2021-43798
criticalDetects a successful Grafana path traversal exploitation
Oracle WebLogic Exploit
criticalDetects access to a webshell dropped into a keystore folder on the WebLogic server
Oracle WebLogic Exploit CVE-2021-2109
criticalDetects the exploitation of the WebLogic server vulnerability described in CVE-2021-2109
OWASSRF Exploitation Attempt Using Public POC - Webserver
criticalDetects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint
ProxyLogon Reset Virtual Directories Based On IIS Log
criticalWhen exploiting this vulnerability with CVE-2021-26858, an SSRF attack is used to manipulate virtual directories
Pulse Secure Attack CVE-2019-11510
criticalDetects CVE-2019-11510 exploitation attempt - URI contains Guacamole
Solarwinds SUPERNOVA Webshell Access
criticalDetects access to SUPERNOVA webshell as described in Guidepoint report
Successful Exchange ProxyShell Attack
criticalDetects URP patterns and status codes that indicate a successful ProxyShell exploitation attack against Exchange servers
WordPress Wp2shell Webshell Plugin Access
criticalDetects post-exploitation access to the wp2shell webshell plugin dropped after successful exploitation of CVE-2026-63030 and CVE-2026-60137. After the pre-auth SQLi-to-admin bridge is established, the attacker can upload a malicious plugin (wp2shell) to the target WordPress instance. At this phase, the attacker accesses the webshell for command execution and persistence.
ADSelfService Exploitation
highDetects suspicious access to URLs that was noticed in cases in which attackers exploitated the ADSelfService vulnerability CVE-2021-40539
Apache Spark Shell Command Injection - Weblogs
highDetects attempts to exploit an apache spark server via CVE-2014-6287 from a weblogs perspective
Atlassian Bitbucket Command Injection Via Archive API
highDetects attempts to exploit the Atlassian Bitbucket Command Injection CVE-2022-36804
Cisco ASA FTD Exploit CVE-2020-3452
highDetects exploitation attempts on Cisco ASA FTD systems exploiting CVE-2020-3452 with a status code of 200 (sccessful exploitation)
Cross Site Scripting Strings
highDetects XSS attempts injected via GET requests in access logs
CVE-2020-0688 Exploitation Attempt
highDetects CVE-2020-0688 Exploitation attempts
CVE-2021-21972 VSphere Exploitation
highDetects the exploitation of VSphere Remote Code Execution vulnerability as described in CVE-2021-21972
CVE-2021-21978 Exploitation Attempt
highDetects the exploitation of the VMware View Planner vulnerability described in CVE-2021-21978
CVE-2021-41773 Exploitation Attempt
highDetects exploitation of flaw in path normalization in Apache HTTP server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the expected document root. If files outside of the document root are not protected by "require all denied" these requests can succeed. Additionally this flaw could leak the source of interpreted files like CGI scripts. This issue is known to be exploited in the wild. This issue only affects Apache 2.4.49 and not earlier versions.
CVE-2022-31656 VMware Workspace ONE Access Auth Bypass
highDetects the exploitation of VMware Workspace ONE Access Authentication Bypass vulnerability as described in CVE-2022-31656 VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
CVE-2023-46747 Exploitation Activity - Webserver
highDetects exploitation activity of CVE-2023-46747 an unauthenticated remote code execution vulnerability in F5 BIG-IP.
CVE-2023-4966 Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
highDetects exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs by looking for a very long host header string.
CVE-2024-1212 Exploitation - Progress Kemp LoadMaster Unauthenticated Command Injection
highDetects potential exploitation of CVE-2024-1709 an unauthenticated command injection in Progress Kemp LoadMaster. It looks for GET requests to '/access/set' API with the parameters 'param=enableapi' and 'value=1' as well as an "Authorization" header with a base64 encoded value with an uncommon character.
DEWMODE Webshell Access
highDetects access to DEWMODE webshell as described in FIREEYE report
Exchange Exploitation Used by HAFNIUM
highDetects exploitation attempts in Exchange server logs as described in blog posts reporting on HAFNIUM group activity
Exchange ProxyShell Pattern
highDetects URL patterns that could be found in ProxyShell exploitation attempts against Exchange servers (failed and successful)
Exploitation Attempt Of CVE-2023-46214 Using Public POC Code
highDetects exploitation attempt of CVE-2023-46214, a remote code execution (RCE) in Splunk Enterprise through insecure XML parsing using known public proof of concept code
Exploitation of CVE-2021-26814 in Wazuh
highDetects the exploitation of the Wazuh RCE vulnerability described in CVE-2021-26814
Java Payload Strings
highDetects possible Java payloads in web access logs
JNDIExploit Pattern
highDetects exploitation attempt using the JNDI-Exploit-Kit
Log4j RCE CVE-2021-44228 Generic
highDetects exploitation attempt against log4j RCE vulnerability reported as CVE-2021-44228 (Log4Shell)
Log4j RCE CVE-2021-44228 in Fields
highDetects exploitation attempt against log4j RCE vulnerability reported as CVE-2021-44228 in different header fields found in web server logs (Log4Shell)
MOVEit CVE-2023-34362 Exploitation Attempt - Potential Web Shell Request
highDetects get requests to specific files used during the exploitation of MOVEit CVE-2023-34362
Oracle WebLogic Exploit CVE-2020-14882
highDetects exploitation attempts on WebLogic servers
Potential Centos Web Panel Exploitation Attempt - CVE-2022-44877
highDetects potential exploitation attempts that target the Centos Web Panel 7 Unauthenticated Remote Code Execution CVE-2022-44877
Potential CVE-2021-26084 Exploitation Attempt
highDetects potential exploitation of CVE-2021-260841 a Confluence RCE using OGNL injection
Potential CVE-2022-21587 Exploitation Attempt
highDetects potential exploitation attempts of CVE-2022-21587 an arbitrary file upload vulnerability impacting Oracle E-Business Suite (EBS). CVE-2022-21587 can lead to unauthenticated remote code execution.
Potential CVE-2022-46169 Exploitation Attempt
highDetects potential exploitation attempts that target the Cacti Command Injection CVE-2022-46169
Potential CVE-2023-23752 Exploitation Attempt
highDetects the potential exploitation attempt of CVE-2023-23752 an Improper access check, in web service endpoints in Joomla
Potential CVE-2023-25157 Exploitation Attempt
highDetects a potential exploitation attempt of CVE-2023-25157 a SQL injection in GeoServer
Potential CVE-2023-25717 Exploitation Attempt
highDetects a potential exploitation attempt of CVE-2023-25717 a Remote Code Execution via an unauthenticated HTTP GET Request, in Ruckus Wireless Admin
Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE
highDetects potential exploitation of a chained vulnerability attack targeting Ivanti EPMM 12.5.0.0. CVE-2025-4427 allows unauthenticated access to protected API endpoints via an authentication bypass, which can then be leveraged to trigger CVE-2025-4428 — a remote code execution vulnerability through template injection. This sequence enables unauthenticated remote code execution, significantly increasing the impact of exploitation.
Potential Information Disclosure CVE-2023-43261 Exploitation - Web
highDetects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in access logs.
Potential Java WebShell Upload in SAP NetViewer Server
highDetects potential Java webshell uploads via HTTP requests with Content-Type 'application/octet-stream' and Java file extensions. This behavior might indicate exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution through webshells in SAP NetViewer.
Potential OWASSRF Exploitation Attempt - Webserver
highDetects exploitation attempt of the OWASSRF variant targeting exchange servers It uses the OWA endpoint to access the powershell backend endpoint
Potential SAP NetViewer Webshell Command Execution
highDetects potential command execution via webshell in SAP NetViewer through JSP files with cmd parameter. This rule is created to detect exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution via a webshell.
Pulse Connect Secure RCE Attack CVE-2021-22893
highThis rule detects exploitation attempts using Pulse Connect Secure(PCS) vulnerability (CVE-2021-22893)
Rejetto HTTP File Server RCE
highDetects attempts to exploit a Rejetto HTTP File Server (HFS) via CVE-2014-6287
Server Side Template Injection Strings
highDetects SSTI attempts sent via GET requests in access logs
Sitecore Pre-Auth RCE CVE-2021-42237
highDetects exploitation attempts of Sitecore Experience Platform Pre-Auth RCE CVE-2021-42237 found in Report.ashx
SonicWall SSL/VPN Jarrewrite Exploitation
highDetects exploitation attempts of the SonicWall Jarrewrite Exploit
SQL Injection Strings In URI
highDetects potential SQL injection attempts via GET requests in access logs.
Suspicious Windows Strings In URI
highDetects suspicious Windows strings in URI which could indicate possible exfiltration or webshell communication
TerraMaster TOS CVE-2020-28188
highDetects the exploitation of the TerraMaster TOS vulnerability described in CVE-2020-28188
VMware vCenter Server File Upload CVE-2021-22005
highDetects exploitation attempts using file upload vulnerability CVE-2021-22005 in the VMWare vCenter Server.
Webshell ReGeorg Detection Via Web Logs
highCertain strings in the uri_query field when combined with null referer and null user agent can indicate activity associated with the webshell ReGeorg.
Windows Webshell Strings
highDetects common commands used in Windows webshells
WordPress Wp2shell Exploitation Tool User-Agent
highDetects the hardcoded "wp2shell" User-Agent string used by the wp2shell PoC tool during all phases of CVE-2026-63030 and CVE-2026-60137 exploitation.
CVE-2022-31659 VMware Workspace ONE Access RCE
mediumDetects possible exploitation of VMware Workspace ONE Access Admin Remote Code Execution vulnerability as described in CVE-2022-31659
CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Webserver)
mediumDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
mediumDetects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs.
F5 BIG-IP iControl Rest API Command Execution - Webserver
mediumDetects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which allows the execution of commands on the BIG-IP
Path Traversal Exploitation Attempts
mediumDetects path traversal exploitation attempts
Potential CVE-2021-27905 Exploitation Attempt
mediumDetects exploitation attempt of the CVE-2021-27905 which affects all Apache Solr versions prior to and including 8.8.1.
Potential CVE-2023-27997 Exploitation Indicators
mediumDetects indicators of potential exploitation of CVE-2023-27997 in Frotigate weblogs. To avoid false positives it is best to look for successive requests to the endpoints mentioned as well as weird values of the "enc" parameter
Potential CVE-2023-46214 Exploitation Attempt
mediumDetects potential exploitation of CVE-2023-46214, a remote code execution (RCE) in Splunk Enterprise through insecure XML parsing
RedTail Cryptominer User-Agent
mediumDetects inbound web requests using the "libredtail-http" User-Agent. libredtail-http is a unique User-Agent string associated with a campaign of automated, malicious scans and attacks targeting exposed container environments and web applications,notably identified in activities stemming from late 2024 through early 2026. It is primarily used by the RedTail cryptominer malware to identify and exploit vulnerabilities for deploying cryptocurrency miners.
SharePoint ToolShell CVE-2025-53770 Exploitation - Web IIS
mediumDetects access to vulnerable SharePoint components potentially being exploited in CVE-2025-53770 through IIS web server logs. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
Source Code Enumeration Detection by Keyword
mediumDetects source code enumeration that use GET requests by keyword searches in URL strings
Successful IIS Shortname Fuzzing Scan
mediumWhen IIS uses an old .Net Framework it's possible to enumerate folders with the symbol "~"
Suspicious User-Agents Related To Recon Tools
mediumDetects known suspicious (default) user-agents related to scanning/recon tools
WordPress Wp2shell REST Batch Endpoint Exploitation
mediumDetects exploitation attempts against the WordPress REST batch endpoint (CVE-2026-63030, CVE-2026-60137) using the wp2shell PoC tool. The tool sends POST requests to the batch endpoint via the ?rest_route=/batch/v1 query parameter, covering all attack phases from initial probe through SQL injection and pre-auth admin creation. A 207 response confirms the endpoint is active on the target.
Zimbra Collaboration Suite Email Server Unauthenticated RCE
mediumDetects an attempt to leverage the vulnerable servlet "mboximport" for an unauthenticated remote command injection