Detection of Potentially Unwanted Application (PUA) via HTTP User-Agent Analysis
This detection analytic identifies Potentially Unwanted Applications by monitoring for specific HTTP User-Agent strings in web logs, which can signify unauthorized tool usage or active compromise on the network.
This detection focuses on identifying the use of Potentially Unwanted Applications (PUA) by analyzing HTTP User-Agent headers found within web or proxy logs. Attackers often utilize specific tools during the reconnaissance, exploitation, or C2 phases of an intrusion, many of which transmit unique or recognizable User-Agent strings. The presence of these identifiers in corporate network traffic is frequently associated with malicious activity, including ransomware operations such as BlackSuit and Cactus, as well as privilege escalation attempts. By comparing incoming User-Agent strings against a known list of PUA signatures, security teams can pinpoint endpoints that are either running unauthorized software or are being utilized as proxies for malicious infrastructure. This detection capability is designed to trigger when a host performs a request using a User-Agent associated with known unwanted software, allowing for early intervention in the intrusion lifecycle.
Impact
Successful exploitation of compromised hosts or the execution of PUA can lead to unauthorized data exfiltration, lateral movement, or the deployment of ransomware. Identifying these tools early allows defenders to isolate affected assets before threat actors can achieve their final objectives, such as encryption or long-term persistence in the environment.
Recommendation
- Implement ingestion of web and proxy logs into your security platform's Web Datamodel to facilitate centralized traffic analysis.
- Deploy the provided detection logic to flag occurrences of PUA-associated User-Agents within the network environment.
- Establish an allowlist for known-good, internally developed tooling that may use non-standard User-Agents to reduce noise in high-traffic environments.
- Perform investigation on hosts identified as sources of PUA traffic, focusing on the parent process that initiated the network request to determine if the activity is authorized.
Immediate actions
Review current proxy/web log ingestion to ensure User-Agent data is present in the Web Datamodel.
Threat Hunt
Identify all unique User-Agent strings in the last 30 days and cross-reference with known PUA lists.
Data: Proxy/Web server logs
Enrichment needed
- PUA User-Agent reference list (CTI) Ensure the detection utilizes the most current list of malicious/unwanted User-Agents.