Exchange CVE-2026-45504 SSRF - w3wp.exe Outbound WOPI/WAC Requests
This rule detects outgoing network connections from the IIS worker process (w3wp.exe) to public-facing URLs that match common Microsoft Office WOPI (Web Application Open Platform Interface) request patterns, but are directed to domains other than trusted Microsoft-affiliated infrastructure. This behavior can be indicative of a Server-Side Request Forgery (SSRF) attempt, where an attacker tries to coerce the server into making unauthorized requests to external resources.
Microsoft Sentinel (KQL)

