Skip to content
← LibraryTechnique entry
W-SSRFLateral Movement

Server-Side Request Forgery (SSRF)

App fetches a URL controlled by the user — pivot to internal services unreachable from the internet.

§ Where this technique fits

W-SSRF is catalogued under the Lateral Movement tactic of the offensive-security kill-chain. It appears in 4 approved dossiers in the registry, typically at step 1.3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    IMDSv1 Credential Theft
    C-IMDS-V1 · Credential Access
    seen 2×
  2. 02
    SSRF → Cloud IMDS
    W-SSRF-IMDS · Lateral Movement
    seen 1×
  3. 03
    SSRF → Internal Service Exploit
    W-SSRF-INTERNAL · Lateral Movement
    seen 1×