{"id":"b923f7d6-ac89-4a50-a71a-89fb846b4aa8","title":"HackTool - Empire UserAgent URI Combo","description":"Detects user agent and URI paths used by empire agents","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2020-07-13","modified":"2024-02-26","tags":["attack.command-and-control","attack.t1071.001"],"technique_ids":["T1071.001"],"logsource":{"category":"proxy"},"falsepositives":["Valid requests with this exact user agent to server scripts of the defined names"],"references":["https://github.com/BC-SECURITY/Empire"],"source_path":"rules/web/proxy_generic/proxy_hktl_empire_ua_uri_patterns.yml","source_sha256":"8d6f323aadd24ccb30f0027dce5b2443784d13160769bad48196c1798784bee5","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/web/proxy_generic/proxy_hktl_empire_ua_uri_patterns.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: HackTool - Empire UserAgent URI Combo\nid: b923f7d6-ac89-4a50-a71a-89fb846b4aa8\nstatus: test\ndescription: Detects user agent and URI paths used by empire agents\nreferences:\n    - https://github.com/BC-SECURITY/Empire\nauthor: Florian Roth (Nextron Systems)\ndate: 2020-07-13\nmodified: 2024-02-26\ntags:\n    - attack.command-and-control\n    - attack.t1071.001\nlogsource:\n    category: proxy\ndetection:\n    selection:\n        c-useragent: 'Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko'\n        cs-uri:\n            - '/admin/get.php'\n            - '/news.php'\n            - '/login/process.php'\n        cs-method: 'POST'\n    condition: selection\nfalsepositives:\n    - Valid requests with this exact user agent to server scripts of the defined names\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1071.001","id":"T1071.001","name":"Web Protocols","page":"techniques/enterprise/T1071.001/"}],"data_path":"data/detection-rules/b923f7d6-ac89-4a50-a71a-89fb846b4aa8.json","kind":"sigma"}
