Skip to content

Latest commit

 

History

History
59 lines (52 loc) · 3.24 KB

LEGACY-S00013.md

File metadata and controls

59 lines (52 loc) · 3.24 KB

Rules: Connection to High Entropy Domain

Description

An HTTP connection was made to a high entropy domain name. Entropy is a measure of randomness, DGA domains used by malware (i.e. g46mbrrzpfszonuk) often have high entropy.

Additional Details

Detail Value
Type Match
Category Exfiltration
Apply Risk to Entities srcDevice_ip
Signal Name Connection to High Entropy Domain
Summary Expression Domain: {{http_url_rootDomain}} has high entropy
Score/Severity Static: 5
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0010, _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1568, _mitreAttackTechnique:T1568.002

Vendors and Products

Fields Used

Origin Field
Normalized Schema http_url_alexaRank
Normalized Schema http_url_entropyRootDomain
Normalized Schema listMatches
Normalized Schema srcDevice_ip