Created
September 22, 2020 15:26
-
-
Save NSkelsey/eda2586e20542baa34770619199e5dc0 to your computer and use it in GitHub Desktop.
Simple zeek script
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
@load base/protocols/http | |
module EvilUserAgents; | |
export { | |
const evil_user_agents = /curl\/[0-9.]+/ &redef; | |
} | |
event HTTP::log_http(rec: HTTP::Info) | |
{ | |
if ( evil_user_agents in rec$user_agent ) { | |
local ua = rec$user_agent; | |
local msg = fmt("%s used the evil UA: %s", rec$id$orig_h, ua); | |
print(msg); | |
} | |
} |
Author
NSkelsey
commented
Sep 22, 2020
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment