Detection Logic
alert any $EXTERNAL_NET any -> $HOME_NET any (msg:"[ZSCALER] FOCA User-Agent"; content:"requestClientApplication
| 3d
| FOCA
| 0d 0a
| "; reference:url,blog.bannasties.com/2013/08/vulnerability-scans/; parse_src_ip: 2; parse_dst_ip: 1; program: CEF; content: "Zscaler"; content:"act=Allowed"; default_dst_port: $HTTP_PORT; default_proto: tcp; xbits: set,exploit_attempt,track ip_src, expire 86400; classtype:attempted-recon; sid:5003185; rev:3; metadata: mitre_technique_id T1043, mitre_technique_id T1105;) Field Validations
Loading…
Comments (0)
Loading comments...