Exchange CVE-2026-45504 w3wp.exe Sensitive File Read via SSRF Injection
This rule detects when the Internet Information Services (IIS) worker process (w3wp.exe) accesses sensitive files such as 'web.config', 'applicationHost.config', or 'win.ini'. Unauthorized access to these files by the IIS process can be an indicator of a web shell or other malicious post-exploitation activity attempting to steal credentials, application secrets, or system configuration information.
Microsoft Sentinel (KQL)

