SSRF occurs when an application can be tricked into sending an unauthorized HTTP request to an unintended destination. Attackers exploit this by changing URL parameters to point to internal or local system files, such as file:///root/.aws/config . Why Attackers Target AWS Config Files
Use a Security Information and Event Management (SIEM) system to alert on repeated file:// attempts from a single IP.