Proxy HTTP GET traffic using Hello-World/1.0 user-agent (possible scraper botnet)

Flags proxy GET requests using the Hello-World/1.0 user-agent, which may indicate automated scraping.

FreeReviewedSigma · Medium · v2
Category
proxy
Author
Joseph A. M. (SigmaHQ), DRL 1.1
Published
2025-08-02
Updated
2026-07-31

ATT&CK techniques

Recon
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags outbound proxy HTTP requests where the method is GET and the user-agent is exactly "Hello-World/1.0". Such automation can be used by scraping infrastructure to blend in with legitimate browsing patterns, making it valuable for identifying potential bot activity. It relies on proxy telemetry containing HTTP method and user-agent fields.

Related detections4 linkedT1595 — drag to rearrange
Suspicious CTF-Framed Vulnerability Scanner User Agent via Webserver
Suspicious Hello-World Scraper Botnet User-Agent in Web Requests
Windows Process Creation: PingCastle Execution with Full Healthcheck Scanners
Windows PingCastle Execution From Suspicious Parent Processes
Proxy HTTP GET traffic using Hello-World/1.0 user-agent (possible scraper botnet)
Pivot detection · T1595 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.