Tag
Cloudreve WebDAV Path Traversal Vulnerability
1 rule 1 TTP 1 CVEA path traversal vulnerability in Cloudreve's WebDAV handler allows attackers with scoped credentials to escape their designated folder and perform unauthorized operations across the entire user namespace.
Goshs WebDAV MOVE Method Bypasses No-Delete Flag
1 rule 1 TTPA critical vulnerability (CVE-2026-64863) in the goshs WebDAV server, affecting versions up to 2.1.3, allows an attacker to bypass the `--no-delete` security flag using the `MOVE` HTTP method, leading to unauthorized deletion of source files or overwriting of existing destination files, impacting data integrity.
ACR Stealer Campaigns Use ClickFix Lures, WebDAV, and Steganography for Credential Theft
2 rules 18 TTPsMicrosoft Defender Experts observed increased ACR Stealer activity from late April to mid-June 2026, using ClickFix social engineering lures in two distinct campaigns to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments via WebDAV-based Python loaders or MSHTA-initiated PowerShell with steganography.
Pimcore WebDAV Asset MOVE Missing Authorization Vulnerability
2 rules 2 TTPsPimcore's WebDAV asset endpoint exposes a `MOVE` operation without authentication, allowing unauthenticated remote attackers to delete assets if they know two existing asset paths in the same directory; Authenticated low-privileged users may also be able to perform unauthorized asset move or overwrite operations because the move path does not enforce `rename`, `delete`, `create`, or `publish` permissions, leading to data loss, content integrity loss, and service disruption.
zrok 'copy' Path Traversal Vulnerability (CVE-2026-45576)
2 rulesA path traversal vulnerability exists in zrok copy (CVE-2026-45576) where an attacker-controlled WebDAV or zrok drive can write files outside the destination root by manipulating the DAV `href` response.
Suspicious Execution of Windows Scripts from WebDAV Share
2 rules 5 TTPsAdversaries may execute Windows scripts directly from a remote WebDAV share to evade detection and avoid writing malicious files to disk; this activity is detected by monitoring process command lines for suspicious WebDAV paths.
Potential Local NTLM Relay via HTTP
2 rules 1 TTPAdversaries may coerce local NTLM authentication over HTTP via WebDAV named-pipe paths (Print Spooler, SRVSVC), then relay credentials to elevate privileges.
Suspicious Execution from WebDAV Share
2 rules 1 TTPThis rule detects attempts to execute content from remote WebDAV shares, where attackers may abuse WebDAV paths, public tunnels, or host@port UNC paths to execute tools or scripts, reducing local staging on the victim's file system.
Rare Connection to WebDAV Target for Credential Access
2 rules 2 TTPsAdversaries may inject WebDAV paths into files or features opened by a user to leak NTLM credentials via forced authentication, and this detection identifies rare connections to WebDAV resources using rundll32.exe.
Mounting Hidden or WebDav Remote Shares via Net.exe
2 rules 4 TTPsAdversaries may use net.exe to mount WebDav or hidden remote shares, indicating lateral movement or preparation for data exfiltration within a Windows environment.