Skip to content

Instantly share code, notes, and snippets.

@clong
Created September 23, 2017 06:41
Show Gist options
  • Star 10 You must be signed in to star a gist
  • Fork 4 You must be signed in to fork a gist
  • Save clong/33b9517b75d238b59fd85fd060514279 to your computer and use it in GitHub Desktop.
Save clong/33b9517b75d238b59fd85fd060514279 to your computer and use it in GitHub Desktop.
Native Windows UserAgents for Threat Hunting
Invoke-WebRequest:
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.14393.1066
System.Net.WebClient.DownloadFile():
None
Start-BitsTransfer:
Microsoft BITS/7.8
certutil.exe:
"Microsoft-CryptoAPI/10.0" & "CertUtil URL Agent"
regsvr32.exe:
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; Win64; x64; Trident/7.0; .NET4.0C; .NET4.0E)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment