diff --git a/rules/web/web_cve_2021_26858_iis_rce.yml b/rules/web/web_cve_2021_26858_iis_rce.yml index d630eafed..12b981800 100644 --- a/rules/web/web_cve_2021_26858_iis_rce.yml +++ b/rules/web/web_cve_2021_26858_iis_rce.yml @@ -19,7 +19,14 @@ detection: - 'schema=Reset' - 'VirtualDirectory' cs-username|endswith: '$' - condition: selection + keywords: + - 'POST' + - '200' + - '/ecp/DDI/DDIService.svc/SetObject' + - 'schema=Reset' + - 'VirtualDirectory' + - '$' + condition: selection or all of keywords falsepositives: - Unlikely level: critical