Skip to content

Web and HTTP Analysis

Searches against web server and HTTP stream data: injection, enumeration, uploads, and traffic analysis. Many use sourcetype=stream:http from Splunk Stream.

Brute forcing attempts against a login

POST requests to a login endpoint, grouped by source and submitted form data.

sourcetype=stream:http <input IP or domain> http_method=POST
| stats count BY src, form_data

File upload / executable transfer

Multipart form uploads, useful for spotting a dropped executable.

index="botsv1" dest_ip="192.168.250.70" sourcetype="stream:http" "multipart/form-data"

Cross-site scripting (XSS)

Requests containing a <script> tag.

index=botsv2 sourcetype="stream:http" "<script>"
| dedup form_data
| table _time form_data src_ip

Decode the payload with urldecode to read it cleanly:

index=botsv2 sourcetype="stream:http" "<script>"
| dedup form_data
| eval decoded=urldecode(form_data)
| table _time decoded src_ip

Narrow to a specific actor or value:

index=botsv2 sourcetype="stream:http" "kevin" "<script>"

CSRF tokens

Background on anti-CSRF tokens and how they are validated: PortSwigger: CSRF tokens.

Visited site containing a keyword

index=botsv2 sourcetype="stream:http" src_ip="10.0.2.101" http_method=GET
| dedup site
| search *beer*

Count of IPs that accessed a domain

index=botsv2 "www.brewertalk.com"
| stats count by src_ip
| sort -count
| head 5

URI paths accessed by an IP

index=botsv2 src_ip=45.77.65.211
| stats values(form_data) count by uri_path