Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
Malformed web requests are sometimes used for reconnaissance to detect the presence of network security devices. A large number of requests from a single source may indicate compromised hosts. Assumes default squid log format.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Syslog |
| ID | edbeec9f-86b9-475d-8a42-cc7b95ad2baa |
| Tactics | Discovery |
| Techniques | T1046 |
| Required Connectors | Syslog, SyslogAma |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
Syslog |
ProcessName contains "squid" |
✓ | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊