ProxyLogon CVE-2021-26855 SSRF Exploitation Attempt Against Exchange
This rule detects inbound HTTP requests targeting Microsoft Exchange Server that contain the specific headers and patterns associated with the ProxyLogon (CVE-2021-26855) Server-Side Request Forgery (SSRF) vulnerability. It specifically monitors for the presence of the 'X-BEResource' header and malformed request structures used by attackers to bypass authentication.
Suricata

