Name:HTTP Scripting Tool User Agent id:04430b4e-5ca8-4e88-98b5-d6bcf54f8393 version:6 date:None author:Raven Tait, Splunk status:production type:Anomaly Description:This Splunk query analyzes web access logs to identify and categorize non-browser user agents, detecting various types of security tools, scripting languages, automation frameworks, and suspicious patterns. This activity can signify malicious actors attempting to interact with web endpoints in non-standard ways. Data_source:
-Nginx Access
search:| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Web where Web.http_user_agent =* NOT Web.http_user_agent IN ( "-", "unknown" ) by Web.http_user_agent Web.dest Web.src Web.status | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Web)` | eval http_user_agent = lower(http_user_agent) | lookup scripting_tools_user_agents tool_user_agent AS http_user_agent OUTPUT tool | where isnotnull(tool) | stats count min(firstTime) as first_seen max(lastTime) as last_seen values(tool) as tool by http_user_agent dest src status | `security_content_ctime(first_seen)` | `security_content_ctime(last_seen)` | `http_scripting_tool_user_agent_filter`