Rules: Suspicious HTTP User-Agent
Common administrative tools may be used by malware authors and attackers who use live-off-the-land methods to operate on victim networks.
Detail | Value |
---|---|
Type | Match |
Category | Execution |
Apply Risk to Entities | device_ip, srcDevice_ip, dstDevice_ip, device_hostname, srcDevice_hostname, dstDevice_hostname, user_username, dstDevice_hostname, dstDevice_ip |
Signal Name | Suspicious HTTP User-Agent |
Summary Expression | Suspicious user agent from IP: {{srcDevice_ip}} user agent: {{http_userAgent}} |
Score/Severity | Static: 1 |
Enabled by Default | True |
Prototype | False |
Tags | _mitreAttackTactic:TA0002, _mitreAttackTactic:TA0004, _mitreAttackTactic:TA0005, _mitreAttackTactic:TA0007, _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1059, _mitreAttackTechnique:T1059.003, _mitreAttackTechnique:T1059.001, _mitreAttackTechnique:T1083, _mitreAttackTechnique:T1132, _mitreAttackTechnique:T1548, _mitreAttackTactic:TA0009, _mitreAttackTechnique:T1213, _mitreAttackTechnique:T1213.001 |
- Akamai - SIEM
- Amazon AWS - API Gateway
- Amazon AWS - Application Load Balancer
- Amazon AWS - CloudFront
- Amazon AWS - CloudTrail
- Amazon AWS - EKS
- Amazon AWS - Elastic Load Balancer
- Amazon AWS - Web Application Firewall (WAF)
- Bro - Bro
- Cisco Systems - Firepower
- Cisco Systems - Meraki
- Cisco Systems - Umbrella
- Cloudflare - Logpush
- Forcepoint - Web Security
- Fortinet - Fortigate
- Gigamon - ThreatInsight
- Google - Google Cloud Platform
- Imperva - Imperva Incapsula
- JFrog - Artifactory
- McAfee - Web Gateway
- Microsoft - Azure
- Microsoft - IIS
- Microsoft - Office 365
- Netskope - Security Cloud
- OISF - Suricata IDS
- Okta - Single Sign-On
- OneLogin - OneLogin Single Sign-On
- Palo Alto Networks - Next Generation Firewall
- Signal Sciences - Web Application Firewall
- Sophos - UTM 9
- Zscaler - Firewall
- Zscaler - Nanolog Streaming Service
Origin | Field |
---|---|
Normalized Schema | device_hostname |
Normalized Schema | device_ip |
Normalized Schema | dstDevice_hostname |
Normalized Schema | dstDevice_ip |
Normalized Schema | http_url_path |
Normalized Schema | http_userAgent |
Normalized Schema | listMatches |
Normalized Schema | lower |
Normalized Schema | srcDevice_hostname |
Normalized Schema | srcDevice_ip |
Normalized Schema | user_username |