title: Windows WebDAV User Agent status: experimental description: Detects WebDav DownloadCradle references: - https://mgreen27.github.io/posts/2018/04/02/DownloadCradle.html author: Florian Roth date: 2018/04/06 logsource: category: proxy detection: selection: UserAgent: 'Microsoft-WebDAV-MiniRedir/*' HttpMethod: 'GET' condition: selection fields: - ClientIP - URL - UserAgent - HttpMethod falsepositives: - Administrative scripts that download files from the Internet - Administrative scripts that retrieve certain website contents - Legitimate WebDAV administration level: high