Name:HTTP PUA User Agent id:21af5447-734f-4549-956b-7a255cb2b032 version:5 date:None author:Raven Tait, Splunk status:production type:Anomaly Description:This Splunk query analyzes web logs to identify and categorize user agents, detecting various types of unwanted applications. This activity can signify possible compromised hosts on the network. Data_source:
-Suricata
search:| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Web WHERE Web.http_user_agent != null BY Web.http_user_agent Web.http_method, Web.url, Web.url_length Web.src, Web.dest | `drop_dm_object_name("Web")` | lookup pua_user_agents pua_user_agent AS http_user_agent OUTPUT tool | where isnotnull(tool) | stats count min(firstTime) as first_seen max(lastTime) as last_seen BY tool url http_user_agent src dest | `security_content_ctime(first_seen)` | `security_content_ctime(last_seen)` | `http_pua_user_agent_filter`
how_to_implement:To successfully implement this search, you need to be ingesting web or proxy logs, or ensure it is being filled by a proxy like device, into the Web Datamodel. For additional filtering, allow list private IP space or restrict by known good. known_false_positives:Noise and false positive can be seen if these programs are allowed to be used within corporate network. In this case, a filter is needed. References: -https://github.com/mthcht/awesome-lists/blob/main/Lists/suspicious_http_user_agents_list.csv drilldown_searches: name:'View the detection results for - "$src$"' search:'%original_detection_search% | search src = "$src$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$src$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Local Privilege Escalation With KrbRelayUp', 'BlackSuit Ransomware', 'Cactus Ransomware', 'Suspicious User Agents']