LoFP LoFP / valid requests with this exact user agent to server scripts of the defined names

Techniques

Sample rules

HackTool - Empire UserAgent URI Combo

Description

Detects user agent and URI paths used by empire agents

Detection logic

condition: selection
selection:
  c-useragent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
  cs-method: POST
  cs-uri:
  - /admin/get.php
  - /news.php
  - /login/process.php