{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/google-cloud-platform-metadata-server/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS EC2 Instance Metadata Service","Google Cloud Platform Metadata Server","Azure Instance Metadata Service"],"_cs_severities":["medium"],"_cs_tags":["ssrf","cloud-security","credential-access"],"_cs_type":"advisory","_cs_vendors":["Amazon","Google","Microsoft"],"content_html":"\u003cp\u003eAttackers frequently exploit server-side request forgery (SSRF) vulnerabilities in web applications to interact with cloud instance metadata services (IMDS). By forcing a web server to make requests to internal-only endpoints such as 169.254.169.254, attackers attempt to retrieve temporary security credentials, identity tokens, and system configuration details associated with the underlying instance role or managed identity. This intelligence highlights the need for robust monitoring of web server access logs for requests containing metadata-related patterns, encoded IP addresses, and specific API paths used by AWS, GCP, and Azure. Successful exploitation allows unauthorized access to cloud resources, privilege escalation, and potential lateral movement within the cloud environment. Defending against this requires identifying the targeted endpoint, verifying if the server responded successfully, and auditing downstream cloud logs for the suspicious use of retrieved credentials.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies a web application endpoint vulnerable to SSRF that accepts user-supplied URLs or query parameters.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a request containing an encoded or direct reference to a cloud metadata service endpoint (e.g., 169.254.169.254).\u003c/li\u003e\n\u003cli\u003eThe web server process parses the malicious input and initiates an outbound HTTP request to the internal cloud metadata service.\u003c/li\u003e\n\u003cli\u003eThe cloud metadata service responds to the server with sensitive data, including IAM role credentials or instance identity tokens.\u003c/li\u003e\n\u003cli\u003eThe web application receives the response and potentially echoes the data back to the attacker or stores it in a location accessible to them.\u003c/li\u003e\n\u003cli\u003eThe attacker captures the returned security tokens or credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the exfiltrated credentials to authenticate against cloud APIs, gaining unauthorized access to the victim's cloud infrastructure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eIf successful, an SSRF attack leads to the compromise of temporary instance-based credentials. This impact typically manifests as unauthorized access to cloud management consoles, data exfiltration from storage buckets, modification of cloud infrastructure, or the compromise of additional cloud services linked to the affected instance's identity.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the implementation of the provided detection logic to identify SSRF attempts against cloud metadata services.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rules below to your SIEM and tune for your environment to identify requests targeting known metadata IP ranges and paths.\u003c/li\u003e\n\u003cli\u003eUse the investigation steps in the rule guidance to correlate detected hits with successful outbound connections from the web server process to internal cloud metadata addresses.\u003c/li\u003e\n\u003cli\u003eEnforce IMDSv2 and hop limits on all cloud instances to mitigate the impact of SSRF and prevent unauthorized credential retrieval.\u003c/li\u003e\n\u003cli\u003eImplement strict outbound allowlists at the application level to block access to link-local and metadata-specific destinations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T06:56:24Z","date_published":"2026-09-15T06:56:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-web-server-cloud-ssrf/","summary":"This detection rule identifies server-side request forgery (SSRF) attempts targeting cloud instance metadata endpoints (IMDS) across multiple web server platforms to harvest cloud credentials.","title":"Detection of SSRF Attempts Targeting Cloud Metadata Services","url":"https://feed.craftedsignal.io/briefs/2026-09-web-server-cloud-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Google Cloud Platform Metadata Server","version":"https://jsonfeed.org/version/1.1"}