Identify instances where a single source is observed using multiple user agents (ASIM Web Session)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This detection mechanism identifies requests originating from a single source within a brief time period that exhibit multiple user agents. Such behavior could indicate unusual web browsing activities performed by unconventional processes

Attribute Value
Type Analytic Rule
Solution Web Session Essentials
ID 813ccf3b-0321-4622-b0bc-63518fd14454
Severity Medium
Status Available
Kind Scheduled
Tactics InitialAccess, CredentialAccess
Techniques T1190, T1133, T1528
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Web Session Essentials