Files
sigma-rules/rules/apm/apm_405_response_method_not_allowed.toml
T
Justin Ibarra 97ee8cc9ac Refresh beats and ecs schemas and default to use latest to validate (#570)
* Refresh beats and ecs schemas and default to use latest to validate
* remove incorrect ecs_version from zoom rule
* remove stale ecs_version from rules
2020-12-01 13:24:20 -09:00

34 lines
1006 B
TOML

[metadata]
creation_date = "2020/02/18"
maturity = "production"
updated_date = "2020/10/26"
[rule]
author = ["Elastic"]
description = """
A request to web application returned a 405 response which indicates the web application declined to process the request
because the HTTP method is not allowed for the resource
"""
false_positives = [
"""
Security scans and tests may result in these errors. Misconfigured or buggy applications may produce large numbers
of these errors. If the source is unexpected, the user unauthorized, or the request unusual, these may indicate
suspicious or malicious activity.
""",
]
index = ["apm-*-transaction*"]
language = "kuery"
license = "Elastic License"
name = "Web Application Suspicious Activity: Unauthorized Method"
references = ["https://en.wikipedia.org/wiki/HTTP_405"]
risk_score = 47
rule_id = "75ee75d8-c180-481c-ba88-ee50129a6aef"
severity = "medium"
tags = ["Elastic", "APM"]
type = "query"
query = '''
http.response.status_code:405
'''