fix: list and add base64 encoded Mozilla keyword
This commit is contained in:
@@ -10,8 +10,9 @@ logsource:
|
||||
category: proxy
|
||||
detection:
|
||||
selection:
|
||||
c-useragent|endswith:
|
||||
c-useragent|endswith:
|
||||
- '='
|
||||
- 'TW96aWxsY' # base64 encoded Mozilla/ as used by YamaBot
|
||||
condition: selection
|
||||
fields:
|
||||
- ClientIP
|
||||
|
||||
Reference in New Issue
Block a user