Yaser, we looked at the User-Agent: DavClnt rule and found there was no distinction between the malicious traffic and traffic from word. Looking at blog.didierstevens.com/2017/11/13/webdav-traffic-to-malicious-sites/ it seems to be expected fallback behavior. We have decided not to publish this rule. 

thanks
Alex McDonnell
TALOS