ProxyLogon (CVE-2021-26855) Exchange Exploitation Attempt

Detects incoming HTTP requests to Microsoft Exchange servers that match patterns indicative of exploitation attempts for the ProxyLogon SSRF vulnerability (CVE-2021-26855). This includes detecting specific manipulation of the Autodiscover service and the injection of X-BEResource or X-AnonResource-Backend headers, which were commonly used during the initial access phase of this campaign.