This rule detects suspicious Windows NT version 9 in the User-Agent field of an HTTP request, which does not correspond to a valid Windows version. It will generate an alert if this User-Agent string is seen in an established HTTP session from a home network client to an external server.
This rule detects suspicious Windows NT version 9 in the User-Agent field of an HTTP request, which does not correspond to a valid Windows version. It will generate an alert if this User-Agent string is seen in an established HTTP session from a home network client to an external server.
Original Title
ET INFO Suspicious Windows NT version 9 User-Agent.txt
This rule detects suspicious Windows NT version 9 in the User-Agent field of an HTTP request, which does not correspond to a valid Windows version. It will generate an alert if this User-Agent string is seen in an established HTTP session from a home network client to an external server.
This rule detects suspicious Windows NT version 9 in the User-Agent field of an HTTP request, which does not correspond to a valid Windows version. It will generate an alert if this User-Agent string is seen in an established HTTP session from a home network client to an external server.