LoFP LoFP / t1595

t1595

TitleTags
a misconfgured network application or firewall may trigger this alert. security scans or test cycles may trigger this alert.
business workflows that occur very occasionally, and involve an unusual surge in network traffic, can trigger this alert. a new business workflow or a surge in business activity may trigger this alert. a misconfigured network application or firewall may trigger this alert.
if you have front-facing proxies that provide authentication and tls, this rule would need to be tuned to eliminate the source ip address of your reverse-proxy.
internal development or testing scripts. consider filtering by source ip if this is expected from certain systems.
legitimate network monitoring or vulnerability scanning tools that may use this generic user agent.
legitimate security scanning.
unknown