Web Server Cloud Metadata SSRF Request

Detects HTTP requests to web servers whose URL or query string references cloud instance metadata endpoints or equivalent encoded variants. Attackers exploit server-side request forgery (SSRF) vulnerabilities in web applications to reach link-local metadata services on AWS, GCP, Azure, and similar cloud providers and harvest temporary credentials, tokens, or instance details.

Elastic rule (View on GitHub)

  1[metadata]
  2creation_date = "2026/07/02"
  3integration = ["nginx", "apache", "apache_tomcat", "iis", "traefik", "zeek"]
  4maturity = "production"
  5updated_date = "2026/09/18"
  6
  7[rule]
  8author = ["Elastic"]
  9description = """
 10Detects HTTP requests to web servers whose URL or query string references cloud instance metadata endpoints or
 11equivalent encoded variants. Attackers exploit server-side request forgery (SSRF) vulnerabilities in web applications
 12to reach link-local metadata services on AWS, GCP, Azure, and similar cloud providers and harvest temporary
 13credentials, tokens, or instance details.
 14"""
 15from = "now-9m"
 16index = [
 17    "logs-nginx.access-*",
 18    "logs-apache.access-*",
 19    "logs-apache_tomcat.access-*",
 20    "logs-iis.access-*",
 21    "logs-traefik.access-*",
 22    "logs-zeek.http-*"
 23]
 24language = "eql"
 25license = "Elastic License v2"
 26name = "Web Server Cloud Metadata SSRF Request"
 27references = [
 28    "https://hackingthe.cloud/aws/general-knowledge/intro_metadata_service/",
 29    "https://owasp.org/www-community/attacks/Server_Side_Request_Forgery",
 30]
 31risk_score = 47
 32rule_id = "8670bf41-cb64-4d65-a0d6-78af17cf8f30"
 33severity = "medium"
 34tags = [
 35    "Domain: Web",
 36    "Domain: Cloud",
 37    "Domain: Network",
 38    "Use Case: Threat Detection",
 39    "Tactic: Credential Access",
 40    "Tactic: Initial Access",
 41    "Data Source: Nginx",
 42    "Data Source: Apache",
 43    "Data Source: Apache Tomcat",
 44    "Data Source: IIS",
 45    "Data Source: Traefik",
 46    "Data Source: Zeek",
 47    "Resources: Investigation Guide",
 48    "Noise: High",
 49    "Performance: Fast",
 50    "Profile: Aggressive",
 51    "Threat: Web Application Attack",
 52    "Threat: IMDS Credential Theft",
 53    "Rule Type: Event Correlation (EQL)",
 54    "Service: Nginx",
 55    "Service: IIS",
 56    "Service: Apache Tomcat",
 57    "Service: Apache HTTP Server",
 58]
 59timestamp_override = "event.ingested"
 60type = "eql"
 61
 62query = '''
 63web where (
 64  url.original : (
 65    "*169.254.169.254*", "*169%2e254%2e169%2e254*", "*0xa9fea9fe*", "*0xa9.0xfe.0xa9.0xfe*", 
 66    "*2852039166*", "*0251.0376.0251.0376*", "*::ffff:169.254.169.254*", "*::ffff:a9fe:a9fe*", "*fd00:ec2::254*",
 67    "*100.100.100.200*", "*169.254.170.2*", "*metadata.google.internal*", "*metadata.goog*", "*computeMetadata/v1*",
 68    "*meta-data/iam/security-credentials*", "*meta-data%2Fiam%2Fsecurity-credentials*",
 69    "*latest/meta-data*", "*latest/api/token*"
 70  )
 71  or
 72  url.query : (
 73    "*169.254.169.254*", "*169%2e254%2e169%2e254*", "*0xa9fea9fe*", "*0xa9.0xfe.0xa9.0xfe*", 
 74    "*2852039166*", "*0251.0376.0251.0376*", "*::ffff:169.254.169.254*", "*::ffff:a9fe:a9fe*", "*fd00:ec2::254*",
 75    "*100.100.100.200*", "*169.254.170.2*", "*metadata.google.internal*", "*metadata.goog*", "*computeMetadata/v1*",
 76    "*meta-data/iam/security-credentials*", "*meta-data%2Fiam%2Fsecurity-credentials*",
 77    "*latest/meta-data*", "*latest/api/token*"
 78  )
 79) and source.as.number != 396982  
 80and not (
 81  user_agent.original : ("*ChatGPT-User*", "*GPTBot*", "*ClaudeBot*", "*anthropic-ai*", "*OAI-SearchBot*", "*perplexity.ai*", "*claude-searchbot*", "*anthropic.com*", "*google.com/bot.html*", "*TelegramBot*", "*openai.com/searchbot*", "*LinkedInBot*", "*x.ai/grokbot*", "*Discordbot*", "*Amazonbot*", "*amazonbot*", "*Applebot*", "*Slackbot*", "*Twitterbot*", "*Bytespider*")
 82  and http.response.status_code in (401, 403, 404, 429)
 83)
 84'''
 85
 86note = """## Triage and analysis
 87
 88### Investigating Web Server Cloud Metadata SSRF Request
 89
 90This alert flags inbound HTTP requests to a web server whose `url.original` or `url.query` contains cloud instance
 91metadata addresses, hostnames, or credential paths. A common attacker pattern is exploiting an SSRF vulnerability so
 92the application fetches `http://169.254.169.254/latest/meta-data/iam/security-credentials/` or equivalent GCP and Azure
 93metadata routes, then reuses the returned role credentials against cloud APIs.
 94
 95#### Possible investigation steps
 96
 97- Review `url.original`, `url.query`, `http.request.method`, `http.response.status_code`, and `source.ip` to identify
 98  the injected metadata target, affected route, and whether the server returned a successful response.
 99- URL-decode the request repeatedly and inspect parameters for nested encodings, redirect chains, or wrapper URLs that
100  hide the metadata destination.
101- Map the targeted endpoint to the backend handler and determine whether user-controlled input can influence outbound
102  HTTP requests from the application.
103- Correlate with application, proxy, and outbound network logs around `@timestamp` for connections from the web server
104  process to `169.254.169.254`, `100.100.100.200`, `metadata.google.internal`, or Azure metadata hosts.
105- Check cloud audit, sign-in, or token-issuance telemetry for use of instance role or managed identity credentials
106  shortly after the request.
107- Pivot on `source.ip` and `user_agent.original` for related SSRF, scanning, or exploitation attempts across other web
108  hosts.
109
110### False positive analysis
111
112- Security scanners, authorized penetration tests, or WAF validation may send metadata URLs in test payloads. Confirm the
113  activity aligns with an approved assessment window and source before closing as benign.
114- Internal documentation, error pages, or security training content that echoes metadata URLs in query strings can
115  trigger the rule without an exploitable SSRF path. Verify the application does not perform outbound fetches based on
116  the matched input.
117
118### Response and remediation
119
120- Block the offending `source.ip` at the WAF or reverse proxy and add virtual patches to reject requests containing
121  metadata addresses or credential paths.
122- If exploitation is confirmed, isolate the affected application host, preserve access logs, and rotate any cloud role
123  or managed identity credentials that may have been exposed.
124- Patch or remediate the SSRF vulnerability by enforcing strict outbound allowlists, blocking link-local and metadata
125  destinations, and validating user-supplied URLs.
126- Enforce IMDSv2, hop limits, and least-privilege instance roles to reduce impact if metadata access succeeds.
127"""
128
129[[rule.threat]]
130framework = "MITRE ATT&CK"
131
132[[rule.threat.technique]]
133id = "T1552"
134name = "Unsecured Credentials"
135reference = "https://attack.mitre.org/techniques/T1552/"
136
137[[rule.threat.technique.subtechnique]]
138id = "T1552.005"
139name = "Cloud Instance Metadata API"
140reference = "https://attack.mitre.org/techniques/T1552/005/"
141
142[rule.threat.tactic]
143id = "TA0006"
144name = "Credential Access"
145reference = "https://attack.mitre.org/tactics/TA0006/"
146
147[[rule.threat]]
148framework = "MITRE ATT&CK"
149
150[[rule.threat.technique]]
151id = "T1190"
152name = "Exploit Public-Facing Application"
153reference = "https://attack.mitre.org/techniques/T1190/"
154
155[rule.threat.tactic]
156id = "TA0001"
157name = "Initial Access"
158reference = "https://attack.mitre.org/tactics/TA0001/"

Triage and analysis

Investigating Web Server Cloud Metadata SSRF Request

This alert flags inbound HTTP requests to a web server whose url.original or url.query contains cloud instance metadata addresses, hostnames, or credential paths. A common attacker pattern is exploiting an SSRF vulnerability so the application fetches http://169.254.169.254/latest/meta-data/iam/security-credentials/ or equivalent GCP and Azure metadata routes, then reuses the returned role credentials against cloud APIs.

Possible investigation steps

  • Review url.original, url.query, http.request.method, http.response.status_code, and source.ip to identify the injected metadata target, affected route, and whether the server returned a successful response.
  • URL-decode the request repeatedly and inspect parameters for nested encodings, redirect chains, or wrapper URLs that hide the metadata destination.
  • Map the targeted endpoint to the backend handler and determine whether user-controlled input can influence outbound HTTP requests from the application.
  • Correlate with application, proxy, and outbound network logs around @timestamp for connections from the web server process to 169.254.169.254, 100.100.100.200, metadata.google.internal, or Azure metadata hosts.
  • Check cloud audit, sign-in, or token-issuance telemetry for use of instance role or managed identity credentials shortly after the request.
  • Pivot on source.ip and user_agent.original for related SSRF, scanning, or exploitation attempts across other web hosts.

False positive analysis

  • Security scanners, authorized penetration tests, or WAF validation may send metadata URLs in test payloads. Confirm the activity aligns with an approved assessment window and source before closing as benign.
  • Internal documentation, error pages, or security training content that echoes metadata URLs in query strings can trigger the rule without an exploitable SSRF path. Verify the application does not perform outbound fetches based on the matched input.

Response and remediation

  • Block the offending source.ip at the WAF or reverse proxy and add virtual patches to reject requests containing metadata addresses or credential paths.
  • If exploitation is confirmed, isolate the affected application host, preserve access logs, and rotate any cloud role or managed identity credentials that may have been exposed.
  • Patch or remediate the SSRF vulnerability by enforcing strict outbound allowlists, blocking link-local and metadata destinations, and validating user-supplied URLs.
  • Enforce IMDSv2, hop limits, and least-privilege instance roles to reduce impact if metadata access succeeds.

References

Related rules

to-top