Skip to content

Latest commit

 

History

History
69 lines (62 loc) · 4.07 KB

LEGACY-S00182.md

File metadata and controls

69 lines (62 loc) · 4.07 KB

Rules: Suspicious HTTP User-Agent

Description

Common administrative tools may be used by malware authors and attackers who use live-off-the-land methods to operate on victim networks.

Additional Details

Detail Value
Type Match
Category Execution
Apply Risk to Entities device_ip, srcDevice_ip, dstDevice_ip, device_hostname, srcDevice_hostname, dstDevice_hostname, user_username, dstDevice_hostname, dstDevice_ip
Signal Name Suspicious HTTP User-Agent
Summary Expression Suspicious user agent from IP: {{srcDevice_ip}} user agent: {{http_userAgent}}
Score/Severity Static: 1
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0002, _mitreAttackTactic:TA0004, _mitreAttackTactic:TA0005, _mitreAttackTactic:TA0007, _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1059, _mitreAttackTechnique:T1059.003, _mitreAttackTechnique:T1059.001, _mitreAttackTechnique:T1083, _mitreAttackTechnique:T1132, _mitreAttackTechnique:T1548, _mitreAttackTactic:TA0009, _mitreAttackTechnique:T1213, _mitreAttackTechnique:T1213.001

Vendors and Products

Fields Used

Origin Field
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema dstDevice_hostname
Normalized Schema dstDevice_ip
Normalized Schema http_url_path
Normalized Schema http_userAgent
Normalized Schema listMatches
Normalized Schema lower
Normalized Schema srcDevice_hostname
Normalized Schema srcDevice_ip
Normalized Schema user_username