id: teamwork-takeover info: name: Teamwork Takeover Detection author: pdteam severity: high description: Teamwork takeover was detected. metadata: max-request: 1 tags: takeover,teamwork http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: - type: dsl dsl: - Host != ip - type: word words: - "Oops - We didn't find your site." extractors: - type: dsl dsl: - "resolve(Host, 'cname')" # digest: 490a0046304402200c14959578832299911cfd57d60b8d2742088dcd2a6859ee930dca59c18d3d8102201c8783b996d7e0adbe4fb289016896ba02fc9a8b12f0fab47abb54d96a262fb7:922c64590222798bb761d5b6d8e72950