id: teamwork-takeover info: name: Teamwork Takeover Detection author: pdteam severity: high description: Teamwork takeover was detected. metadata: max-request: 1 tags: takeover,teamwork http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: - type: dsl dsl: - Host != ip - type: word words: - "Oops - We didn't find your site." extractors: - type: dsl dsl: - cname # digest: 490a004630440220212b31588a3bf9adbc6e4558bb1f20e2b58859dba0a44205e774a1f7d590c5c002205eb500a037b808b99c0c35a3d57754200e5d80d1b8c8b874ed522816e40bb996:922c64590222798bb761d5b6d8e72950