Skip to content

Commit 7f415f9

Browse files
Update detections/network/cisco_sa___automated_web_reconnaissance_via_http_access_errors.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
1 parent c60da68 commit 7f415f9

1 file changed

Lines changed: 0 additions & 1 deletion

File tree

detections/network/cisco_sa___automated_web_reconnaissance_via_http_access_errors.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,6 @@ description: |
1010
This analytic detects probable automated web reconnaissance using Cisco Secure Access proxy telemetry.
1111
A high volume of HTTP client errors (401/403/404) across many unique URLs in a short window is consistent with directory/file enumeration behavior generated by tools such as Gobuster, DirBuster, ffuf, or Burp Intruder.
1212
Detecting this pattern helps identify pre-exploitation scanning activity, insider reconnaissance, compromised endpoints performing discovery, and attempts to find hidden administrative paths, APIs, backups, and exposed application files.
13-
Activity is mapped to MITRE ATT&CK T1595 (Active Scanning).
1413
data_source:
1514
- Cisco Secure Access Proxy
1615
search: |-

0 commit comments

Comments
 (0)