LoFP LoFP / administrative scripts that download files from the internet

Techniques

Sample rules

Windows WebDAV User Agent

Description

Detects WebDav DownloadCradle

Detection logic

condition: selection
selection:
  c-useragent|startswith: Microsoft-WebDAV-MiniRedir/
  cs-method: GET

Windows PowerShell User Agent

Description

Detects Windows PowerShell Web Access

Detection logic

condition: selection
selection:
  c-useragent|contains: ' WindowsPowerShell/'