Detect attempts to run vulnerability scanners, etc. based on the Activate Attack Tool pattern group.
Overview
| Priority | Medium |
|---|---|
| Type | Stream |
| Log schema | webfilter |
| Message | 공격툴 접속: $src_ip -> $domain ($result) |
| Referenced objects | Pattern group 공격툴 활성화2 |
Query
1| matchsig field=domain guid="331ac759-22c0-456b-865b-5bbb537d732e" verify=f
2| eval result = strjoin("\n", foreach(valueof(_1, "rule"), _matchsig_result)) | fields - _matchsig_result