Web Recon Scanning of Victim Sites via IIS Logs (T1594)

Detects potential web reconnaissance or scanning activity against Microsoft IIS servers. The rule identifies suspicious behavior by monitoring for high frequencies of distinct URI requests, excessive 404 Not Found status codes indicative of path brute-forcing, and the presence of known security scanning user-agents.