Web Server Cloud Metadata SSRF Request
Detects HTTP requests to web servers whose URL or query string references cloud instance metadata endpoints or equivalent encoded variants. Attackers exploit server-side request forgery (SSRF) vulnerabilities in web applications to reach link-local metadata services on AWS, GCP, Azure, and similar cloud providers and harvest temporary credentials, tokens, or instance details.
Elastic rule (View on GitHub)
1[metadata]
2creation_date = "2026/07/02"
3integration = ["nginx", "apache", "apache_tomcat", "iis", "traefik", "zeek"]
4maturity = "production"
5updated_date = "2026/09/18"
6
7[rule]
8author = ["Elastic"]
9description = """
10Detects HTTP requests to web servers whose URL or query string references cloud instance metadata endpoints or
11equivalent encoded variants. Attackers exploit server-side request forgery (SSRF) vulnerabilities in web applications
12to reach link-local metadata services on AWS, GCP, Azure, and similar cloud providers and harvest temporary
13credentials, tokens, or instance details.
14"""
15from = "now-9m"
16index = [
17 "logs-nginx.access-*",
18 "logs-apache.access-*",
19 "logs-apache_tomcat.access-*",
20 "logs-iis.access-*",
21 "logs-traefik.access-*",
22 "logs-zeek.http-*"
23]
24language = "eql"
25license = "Elastic License v2"
26name = "Web Server Cloud Metadata SSRF Request"
27references = [
28 "https://hackingthe.cloud/aws/general-knowledge/intro_metadata_service/",
29 "https://owasp.org/www-community/attacks/Server_Side_Request_Forgery",
30]
31risk_score = 47
32rule_id = "8670bf41-cb64-4d65-a0d6-78af17cf8f30"
33severity = "medium"
34tags = [
35 "Domain: Web",
36 "Domain: Cloud",
37 "Domain: Network",
38 "Use Case: Threat Detection",
39 "Tactic: Credential Access",
40 "Tactic: Initial Access",
41 "Data Source: Nginx",
42 "Data Source: Apache",
43 "Data Source: Apache Tomcat",
44 "Data Source: IIS",
45 "Data Source: Traefik",
46 "Data Source: Zeek",
47 "Resources: Investigation Guide",
48 "Noise: High",
49 "Performance: Fast",
50 "Profile: Aggressive",
51 "Threat: Web Application Attack",
52 "Threat: IMDS Credential Theft",
53 "Rule Type: Event Correlation (EQL)",
54 "Service: Nginx",
55 "Service: IIS",
56 "Service: Apache Tomcat",
57 "Service: Apache HTTP Server",
58]
59timestamp_override = "event.ingested"
60type = "eql"
61
62query = '''
63web where (
64 url.original : (
65 "*169.254.169.254*", "*169%2e254%2e169%2e254*", "*0xa9fea9fe*", "*0xa9.0xfe.0xa9.0xfe*",
66 "*2852039166*", "*0251.0376.0251.0376*", "*::ffff:169.254.169.254*", "*::ffff:a9fe:a9fe*", "*fd00:ec2::254*",
67 "*100.100.100.200*", "*169.254.170.2*", "*metadata.google.internal*", "*metadata.goog*", "*computeMetadata/v1*",
68 "*meta-data/iam/security-credentials*", "*meta-data%2Fiam%2Fsecurity-credentials*",
69 "*latest/meta-data*", "*latest/api/token*"
70 )
71 or
72 url.query : (
73 "*169.254.169.254*", "*169%2e254%2e169%2e254*", "*0xa9fea9fe*", "*0xa9.0xfe.0xa9.0xfe*",
74 "*2852039166*", "*0251.0376.0251.0376*", "*::ffff:169.254.169.254*", "*::ffff:a9fe:a9fe*", "*fd00:ec2::254*",
75 "*100.100.100.200*", "*169.254.170.2*", "*metadata.google.internal*", "*metadata.goog*", "*computeMetadata/v1*",
76 "*meta-data/iam/security-credentials*", "*meta-data%2Fiam%2Fsecurity-credentials*",
77 "*latest/meta-data*", "*latest/api/token*"
78 )
79) and source.as.number != 396982
80and not (
81 user_agent.original : ("*ChatGPT-User*", "*GPTBot*", "*ClaudeBot*", "*anthropic-ai*", "*OAI-SearchBot*", "*perplexity.ai*", "*claude-searchbot*", "*anthropic.com*", "*google.com/bot.html*", "*TelegramBot*", "*openai.com/searchbot*", "*LinkedInBot*", "*x.ai/grokbot*", "*Discordbot*", "*Amazonbot*", "*amazonbot*", "*Applebot*", "*Slackbot*", "*Twitterbot*", "*Bytespider*")
82 and http.response.status_code in (401, 403, 404, 429)
83)
84'''
85
86note = """## Triage and analysis
87
88### Investigating Web Server Cloud Metadata SSRF Request
89
90This alert flags inbound HTTP requests to a web server whose `url.original` or `url.query` contains cloud instance
91metadata addresses, hostnames, or credential paths. A common attacker pattern is exploiting an SSRF vulnerability so
92the application fetches `http://169.254.169.254/latest/meta-data/iam/security-credentials/` or equivalent GCP and Azure
93metadata routes, then reuses the returned role credentials against cloud APIs.
94
95#### Possible investigation steps
96
97- Review `url.original`, `url.query`, `http.request.method`, `http.response.status_code`, and `source.ip` to identify
98 the injected metadata target, affected route, and whether the server returned a successful response.
99- URL-decode the request repeatedly and inspect parameters for nested encodings, redirect chains, or wrapper URLs that
100 hide the metadata destination.
101- Map the targeted endpoint to the backend handler and determine whether user-controlled input can influence outbound
102 HTTP requests from the application.
103- Correlate with application, proxy, and outbound network logs around `@timestamp` for connections from the web server
104 process to `169.254.169.254`, `100.100.100.200`, `metadata.google.internal`, or Azure metadata hosts.
105- Check cloud audit, sign-in, or token-issuance telemetry for use of instance role or managed identity credentials
106 shortly after the request.
107- Pivot on `source.ip` and `user_agent.original` for related SSRF, scanning, or exploitation attempts across other web
108 hosts.
109
110### False positive analysis
111
112- Security scanners, authorized penetration tests, or WAF validation may send metadata URLs in test payloads. Confirm the
113 activity aligns with an approved assessment window and source before closing as benign.
114- Internal documentation, error pages, or security training content that echoes metadata URLs in query strings can
115 trigger the rule without an exploitable SSRF path. Verify the application does not perform outbound fetches based on
116 the matched input.
117
118### Response and remediation
119
120- Block the offending `source.ip` at the WAF or reverse proxy and add virtual patches to reject requests containing
121 metadata addresses or credential paths.
122- If exploitation is confirmed, isolate the affected application host, preserve access logs, and rotate any cloud role
123 or managed identity credentials that may have been exposed.
124- Patch or remediate the SSRF vulnerability by enforcing strict outbound allowlists, blocking link-local and metadata
125 destinations, and validating user-supplied URLs.
126- Enforce IMDSv2, hop limits, and least-privilege instance roles to reduce impact if metadata access succeeds.
127"""
128
129[[rule.threat]]
130framework = "MITRE ATT&CK"
131
132[[rule.threat.technique]]
133id = "T1552"
134name = "Unsecured Credentials"
135reference = "https://attack.mitre.org/techniques/T1552/"
136
137[[rule.threat.technique.subtechnique]]
138id = "T1552.005"
139name = "Cloud Instance Metadata API"
140reference = "https://attack.mitre.org/techniques/T1552/005/"
141
142[rule.threat.tactic]
143id = "TA0006"
144name = "Credential Access"
145reference = "https://attack.mitre.org/tactics/TA0006/"
146
147[[rule.threat]]
148framework = "MITRE ATT&CK"
149
150[[rule.threat.technique]]
151id = "T1190"
152name = "Exploit Public-Facing Application"
153reference = "https://attack.mitre.org/techniques/T1190/"
154
155[rule.threat.tactic]
156id = "TA0001"
157name = "Initial Access"
158reference = "https://attack.mitre.org/tactics/TA0001/"
Triage and analysis
Investigating Web Server Cloud Metadata SSRF Request
This alert flags inbound HTTP requests to a web server whose url.original or url.query contains cloud instance
metadata addresses, hostnames, or credential paths. A common attacker pattern is exploiting an SSRF vulnerability so
the application fetches http://169.254.169.254/latest/meta-data/iam/security-credentials/ or equivalent GCP and Azure
metadata routes, then reuses the returned role credentials against cloud APIs.
Possible investigation steps
- Review
url.original,url.query,http.request.method,http.response.status_code, andsource.ipto identify the injected metadata target, affected route, and whether the server returned a successful response. - URL-decode the request repeatedly and inspect parameters for nested encodings, redirect chains, or wrapper URLs that hide the metadata destination.
- Map the targeted endpoint to the backend handler and determine whether user-controlled input can influence outbound HTTP requests from the application.
- Correlate with application, proxy, and outbound network logs around
@timestampfor connections from the web server process to169.254.169.254,100.100.100.200,metadata.google.internal, or Azure metadata hosts. - Check cloud audit, sign-in, or token-issuance telemetry for use of instance role or managed identity credentials shortly after the request.
- Pivot on
source.ipanduser_agent.originalfor related SSRF, scanning, or exploitation attempts across other web hosts.
False positive analysis
- Security scanners, authorized penetration tests, or WAF validation may send metadata URLs in test payloads. Confirm the activity aligns with an approved assessment window and source before closing as benign.
- Internal documentation, error pages, or security training content that echoes metadata URLs in query strings can trigger the rule without an exploitable SSRF path. Verify the application does not perform outbound fetches based on the matched input.
Response and remediation
- Block the offending
source.ipat the WAF or reverse proxy and add virtual patches to reject requests containing metadata addresses or credential paths. - If exploitation is confirmed, isolate the affected application host, preserve access logs, and rotate any cloud role or managed identity credentials that may have been exposed.
- Patch or remediate the SSRF vulnerability by enforcing strict outbound allowlists, blocking link-local and metadata destinations, and validating user-supplied URLs.
- Enforce IMDSv2, hop limits, and least-privilege instance roles to reduce impact if metadata access succeeds.
References
Related rules
- Web Server Potential SQL Injection Request
- Web Server Potential Remote File Inclusion Activity
- Web Server Potential Spike in Error Response Codes
- Web Server Potential Command Injection Request
- Web Server Suspicious User Agent Requests