id: defaced-website-detect info: name: Defaced Website - Detection author: ggranjus severity: info description: The detected website is defaced. metadata: verified: 'true' max-request: 1 shodan-query: http.title:"Hacked By" tags: miscellaneous,defacement,misc http: - method: GET path: - "{{BaseURL}}" matchers: - type: regex part: body regex: - '(?i).*Hacked( By .+)?<\/title>' extractors: - type: xpath xpath: - '/html/head/title' # digest: 4a0a004730450221008017206eef3294e64b224c423a46620964e66451b66a5c444a1e4fb5050dc10a0220069f2bdb68a10415f4d3ec5eff3478c39ecce08c45f8f02b192463f7867536de:922c64590222798bb761d5b6d8e72950