- IP address of Windows host encoded in web request
This detection will identify network requests in HTTP proxy data that contains Base64 encoded
IP addresses.
Reference URL : IP address of Windows host encoded in web request | Microsoft Sentinel Analytic Rules
- Windows host username encoded in base64 web request
This detection will identify network requests in HTTP proxy data that contains Base64 encoded
usernames from machines in the DeviceEvents table.
Reference URL : Windows host username encoded in base64 web request | Microsoft Sentinel Analytic Rules
could you please help with this above for YARAL Rule Logic..