ProxyShell CVE-2021-34473 Exchange Autodiscover Path Traversal
Detects attempts to exploit the ProxyShell vulnerability (CVE-2021-34473) in Microsoft Exchange servers. The rule identifies malicious path traversal sequences, specifically utilizing encoding techniques like double URL encoding (%25) or dot-dot-slash characters within requests to the Autodiscover service, aimed at bypassing security controls.
Suricata

