HTTP Malware User Agent — Detection Rule

This Splunk query analyzes web logs to identify and categorize user agents, detecting various types of malware. This activity can signify possible compromised hosts on the network.

Read the full analysis on IntelFusions