Name:HTTP Suspicious Tool User Agent id:1ca76190-4997-4d19-b5bc-9e220b70c7d3 version:2 date:2025-10-09 author:Raven Tait, Splunk status:deprecated type:Anomaly Description:This Splunk query analyzes web access logs to identify and categorize non-browser user agents, detecting various types of security tools, scripting languages, automation frameworks, and suspicious patterns. This activity can signify malicious actors attempting to interact with web endpoints in non-standard ways. Data_source:
-Nginx Access
search:`nginx_access_logs` | eval http_user_agent = lower(http_user_agent) | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Web)` | lookup scripting_tools_user_agents tool_user_agent AS http_user_agent OUTPUT tool | where isnotnull(tool) | rename dest_ip as dest | stats count min(firstTime) as first_seen max(lastTime) as last_seen values(tool) as tool by http_user_agent dest src_ip status | `http_suspicious_tool_user_agent_filter`