Terrance DeJesus
ae5ecd5346
[Rule Tuning] AWS suspicious user agents (TruffleHog, Kali CLI/Boto3) ( #5902 )
...
* Expand AWS CloudTrail user-agent rule for TruffleHog and Kali
- Rename rule file to initial_access_suspicious_user_agent_detected_in_cloudtrail.toml
- Rule name: AWS Suspicious User Agent Fingerprint
- Match TruffleHog in user_agent.original (successful API calls)
- Retain Kali Linux distrib#kali fingerprint for aws-cli/Boto3
- Refresh narrative and references (incl. Kudelski Trivy supply-chain analysis)
Same rule_id f80ea920-f6f5-4c8a-9761-84ac97ec0cb2.
Made-with: Cursor
* Apply suggestion from @terrancedejesus
2026-04-03 11:50:28 -04:00
..
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-01-20 15:52:48 -05:00
2026-01-22 15:01:49 -05:00
2025-06-06 14:11:54 -04:00
2026-01-20 15:52:48 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-02-17 16:32:20 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-04-01 09:12:42 -05:00
2026-01-20 15:52:48 -05:00
2026-01-20 15:52:48 -05:00
2026-04-01 09:12:42 -05:00
2026-01-20 15:52:48 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-01-22 15:01:49 -05:00
2026-01-20 15:52:48 -05:00
2025-12-18 11:47:59 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2025-06-27 13:24:27 -04:00
2025-07-18 19:15:36 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2025-07-21 10:12:13 +05:30
2026-01-22 15:01:49 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-04-01 09:12:42 -05:00
2026-01-20 15:52:48 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-04-01 09:12:42 -05:00
2026-01-20 15:52:48 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-20 15:52:48 -05:00
2026-01-20 15:52:48 -05:00
2026-01-20 15:52:48 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-20 15:52:48 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-20 15:52:48 -05:00
2026-04-03 11:50:28 -04:00
2025-09-11 15:54:31 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2025-12-01 15:48:59 -06:00
2025-12-01 15:48:59 -06:00
2026-04-01 09:12:42 -05:00
2025-12-01 15:48:59 -06:00
2026-04-02 09:25:14 -04:00
2021-07-21 15:24:56 -06:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2025-09-11 15:11:40 -04:00
2026-01-20 15:52:48 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-20 15:52:48 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-22 15:01:49 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-20 15:52:48 -05:00
2026-01-20 15:52:48 -05:00
2026-01-20 15:52:48 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-20 15:52:48 -05:00