Suspicious CTF-Framed Vulnerability Scanner User Agent via Webserver

PremiumReviewedSigma · Medium · v1
Category
webserver
Author
HuntRule
Published
2026-06-25
Updated
2026-08-28

ATT&CK techniques

Recon
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects HTTP User-Agents matching the CTF and CVE-hunt framing that attackers use while jailbreaking LLM services and mass-scanning for vulnerabilities. These agents self-identify with capture-the-flag and CVE-scanner labels as part of automated probing. Their presence indicates reconnaissance against internet-facing AI applications.

Related detections4 linkedT1595 — drag to rearrange
Suspicious Hello-World Scraper Botnet User-Agent in Web Requests
Proxy HTTP GET traffic using Hello-World/1.0 user-agent (possible scraper botnet)
Windows Process Creation: PingCastle Execution with Full Healthcheck Scanners
Windows PingCastle Execution From Suspicious Parent Processes
Suspicious CTF-Framed Vulnerability Scanner User Agent via Webserver
Pivot detection · T1595 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.