Detecting File Transfer Zero-Day Exploitation: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from June 2023, written in 2026 with the benefit of hindsight.
Mass exploitation of file transfer products typically targets web interfaces and ends with bulk data downloads. These detections help catch both stages.
Signals worth watching
- Web requests to file transfer applications matching published exploit patterns (vendor and CISA advisories provide indicators).
- New or modified web files (for example, ASPX files) in application directories.
- Database queries or exports far larger than normal.
- Unusual outbound data volumes from file transfer servers.
- New administrative accounts created in the application.
- Requests from IPs listed in threat intelligence for the campaign.
Where the data lives
- Web server and application logs.
- WAF logs.
- Defender for Endpoint / Defender for Servers on the host.
- Network flow logs (NSG or VPC Flow Logs).
A starting query
Large outbound transfers from a specific server:
DeviceNetworkEvents
| where DeviceName in~ ("filetransfer01", "sftp-prod")
| where RemoteIPType == "Public"
| summarize Connections = count(), RemoteIPs = dcount(RemoteIP) by DeviceName, bin(Timestamp, 1h)
Combine with network flow logs for byte counts and compare against baseline.
Response
- Take the service offline or block external access.
- Apply vendor patches and hunt with published indicators.
- Determine what data was accessed and whose it is.
- Engage legal for notification obligations — including obligations to customers whose data you held.