Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
This rule helps to identify instances of empty user agent requests originating from IP addresses that have previously reported user agent at least once within the same time period.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Web Session Essentials |
| ID | 69e53015-a309-4a8f-a94d-df61a9217e2f |
| Tactics | InitialAccess |
| Techniques | T1190, T1133 |
| Source | View on GitHub |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊