HTTP Scripting Tool User Agent: networkNetworkNoneversion:6
This Splunk query analyzes web access logs to identify and categorize non-browser user agents, detecting various types of security tools, scripting languages, automation frameworks, and suspicious patterns. This activity can signify malicious actors attempting to interact with web endpoints in non-standard ways.
HTTP PUA User Agent: networkNetworkNoneversion:5
This Splunk query analyzes web logs to identify and categorize user agents, detecting various types of unwanted applications. This activity can signify possible compromised hosts on the network.
HTTP C2 Framework User Agent: networkNetworkNoneversion:5
This Splunk query analyzes web logs to identify and categorize user agents, detecting various types of c2 frameworks. This activity can signify malicious actors attempting to interact with hosts on the network using known default configurations of command and control tools.
Windows RMM Tool Execution: endpointEndpointNoneversion:2
Detects process creation events of various remote access tools.
Remote management tools, when used for legitimate purposes, can help IT professionals and system administrators remotely access and manage computer systems.
However, threat actors may exploit these tools for malicious purposes.
HTTP RMM User Agent: networkNetworkNoneversion:5
This Splunk query analyzes web logs to identify and categorize user agents, detecting various types of Remote Monitoring and Mangement applications. This activity can signify possible compromised hosts on the network.
HTTP Malware User Agent: networkNetworkNoneversion:5
This Splunk query analyzes web logs to identify and categorize user agents, detecting various types of malware. This activity can signify possible compromised hosts on the network.