Rules: Connection to High Entropy Domain
An HTTP connection was made to a high entropy domain name. Entropy is a measure of randomness, DGA domains used by malware (i.e. g46mbrrzpfszonuk) often have high entropy.
Detail | Value |
---|---|
Type | Match |
Category | Exfiltration |
Apply Risk to Entities | srcDevice_ip |
Signal Name | Connection to High Entropy Domain |
Summary Expression | Domain: {{http_url_rootDomain}} has high entropy |
Score/Severity | Static: 5 |
Enabled by Default | True |
Prototype | False |
Tags | _mitreAttackTactic:TA0010, _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1568, _mitreAttackTechnique:T1568.002 |
- Amazon AWS - Application Load Balancer
- Amazon AWS - Elastic Load Balancer
- Amazon AWS - Network Firewall
- Amazon AWS - Web Application Firewall (WAF)
- Bro - Bro
- CheckPoint - Firewall and VPN
- CheckPoint - URL Filtering
- Cisco Systems - ASA
- Cisco Systems - Firepower
- Cisco Systems - Ironport
- Cisco Systems - Meraki
- Cisco Systems - Umbrella
- Cloudflare - Logpush
- Forcepoint - Web Security
- Fortinet - Fortigate
- Google - Google Cloud Platform
- Juniper - SRX Series Firewall
- McAfee - Web Gateway
- Microsoft - Azure
- Microsoft - IIS
- Netskope - Security Cloud
- Netskope - WebTx
- Palo Alto Networks - Next Generation Firewall
- Proofpoint - Targeted Attack Protection
- Sophos - UTM 9
- Squid - Squid Proxy
- Trend Micro - Apex Central
- Zscaler - Firewall
- Zscaler - Nanolog Streaming Service
Origin | Field |
---|---|
Normalized Schema | http_url_alexaRank |
Normalized Schema | http_url_entropyRootDomain |
Normalized Schema | listMatches |
Normalized Schema | srcDevice_ip |