Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Looks for requests to URLs that HoneyLabs extracted from payloads captured by its honeypot sensors. These are the addresses attacker tooling actually fetched its second stage from, so a hit generally indicates post-compromise activity rather than inbound scanning and is worth investigating on the requesting host.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | HoneyLabs |
| ID | 3c8b6e21-45af-4d90-8b17-9e2f7c1a4d55 |
| Tactics | CommandAndControl |
| Techniques | T1105 |
| Required Connectors | ThreatIntelligenceTaxii |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
CommonSecurityLog |
✓ | ✓ | ✓ |
ThreatIntelIndicators |
✓ | ✓ | ✗ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊