-
Notifications
You must be signed in to change notification settings - Fork 0
License
elcabezzonn/http-header-count
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
* This is a modification to the header-names.zeek script. The objective of this script is to count the headers of the http request from the originator. This could help with identifying anomalous activity in your environment. For example, a few years ago there was malware (forgot which one) that leveraged a powershell cmldet ( forget which one sorry!) that downloaded an executable from attacker controlled infrastructure. The http header count was always two and combining it with a trans depth of 1 meaning non pipelined request, no referrer and filetype dos exec, it allowed you to query for interesting results.
About
No description, website, or topics provided.
Resources
License
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published