Cobalt Strike Default HTTP Beacon GET /ca /submit.php /updates.rss

This rule detects network traffic originating from internal hosts to external destinations consistent with default Cobalt Strike HTTP Beacon communication patterns. It specifically looks for GET requests containing URI paths commonly associated with default Cobalt Strike profiles (ca, submit.php, updates.rss) combined with a specific, hardcoded User-Agent string associated with Cobalt Strike's default configuration.