Threat Hunting - Suspicious User Agents | by mthcht | Detect FYI
A User-Agent string is a line of text that a browser or application sends to a web server to identify itself. It typically includes the name and version of the browser/application, the operating system, and the language. It’s constructed as a list of product tokens (keywords) with optional comments that provide further detail. Tokens are typically separated by spaces, and comments are enclosed in parentheses. Each part of the User-Agent string helps the server determine how to deliver content in a compatible format for the client’s software environment. Back to the early days of the internet when browsers were competing for market share, it was straightforward, but as competition increased, browsers started to mimic each other’s strings to bypass compatibility issues. For example, Mozilla’s format, “Mozilla/5.0 (…)”, became a standard prefix for many browsers, regardless of their actual connection to Mozilla. A classic example of how user-agents have been manipulated for broader web co
User Agent Threat Hunting Threat Intelligence Detection Engineering Splunk Threat Hunting - Suspicious User Agents mthcht 14 min read · Jan 1, 2024 -- 3 Listen Share Press enter or click to view image in full size What is a User-Agent ? A User-Agent string is a line of text that a browser or application sends to a web server to identify itself. It typically includes the name and version of the browser/application, the operating system, and the language. It’s constructed as a list of product tokens (keywords) with optional comments that provide further detail. Tokens are typically separated by
related reading
- How rare is a rare HTTP agent? Context-rich alerts because of math – Opstune.comopstune.com
- Unsupervised Machine Learning with Splunk: the cluster command | by Alex Teixeira | Detect FYIdetect.fyi
- Lakera – Test your AI hacking skillsgandalf.lakera.ai
- Is Agentic: AI Agent Readiness Score for your Site and Appis-agentic.com
- AI Agent Bankrupted Their Operator While Trying to Scan DN42 - Lan Tian @ Bloglantian.pub
- Superagent - Security for AI-native developerssuperagent.sh
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Shodanshodan.io
- Frontier AI Cybersecurity Observatorycybergym.io
- EmailOSINT: Reverse email lookups in secondsemailosint.org
- mitmproxy - an interactive HTTPS proxymitmproxy.org
- Introducing Precursor: detecting agentic behavior with continuous client-side signalsblog.cloudflare.com