id: helpscout-takeover info: name: helpscout takeover detection author: pdteam severity: high description: helpscout takeover was detected. reference: - https://github.com/EdOverflow/can-i-take-over-xyz metadata: max-request: 1 tags: takeover http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: - type: dsl dsl: - Host != ip - type: word words: - "No settings were found for this company:" # digest: 4a0a00473045022100f82db3b5d07dfbfb6f11abb9f0abc7a1991698b51abcdbe03bc6b13f41d7710b022017ff27474089ced18f311f6798e2ed903d149f3da6ccd0efd91bab91c6c4d21f:922c64590222798bb761d5b6d8e72950