Skip to content

Latest commit

 

History

History
48 lines (41 loc) · 2.12 KB

LEGACY-S00008.md

File metadata and controls

48 lines (41 loc) · 2.12 KB

Rules: Possible Dynamic DNS Domain

Description

This rule looks for DNS query/reply domains which appear to be associated with a dynamic DNS service.

Additional Details

Detail Value
Type Match
Category Command and Control
Apply Risk to Entities device_hostname, device_ip, srcDevice_hostname, srcDevice_ip, user_username
Signal Name Possible Dynamic DNS Domain
Summary Expression Possible dynamic DNS domain for URL: {{dns_queryDomain}}
Score/Severity Static: 1
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1568, _mitreAttackTechnique:T1568.001, _mitreAttackTechnique:T1568.002, _mitreAttackTechnique:T1568.003

Vendors and Products

Fields Used

Origin Field
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema dns_queryDomain_alexaRank
Normalized Schema dns_queryDomain_possibleDynDns
Normalized Schema dns_replyDomain_alexaRank
Normalized Schema dns_replyDomain_possibleDynDns
Normalized Schema srcDevice_hostname
Normalized Schema srcDevice_ip
Normalized Schema user_username