Rules: Possible Dynamic URL Domain
This rule looks for URL/refferer domains which appear to be associated with a dynamic DNS service.
Detail | Value |
---|---|
Type | Templated Match |
Category | Command and Control |
Apply Risk to Entities | device_hostname, device_ip, srcDevice_hostname, srcDevice_ip, user_username |
Signal Name | Possible Dynamic URL Domain |
Summary Expression | Possible dynamic DNS domain for URL: {{http_url_fqdn}} |
Score/Severity | Static: 1 |
Enabled by Default | True |
Prototype | False |
Tags | _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1568, _mitreAttackTechnique:T1568.001, _mitreAttackTechnique:T1568.002, _mitreAttackTechnique:T1568.003 |
- Akamai - SIEM
- Amazon AWS - Application Load Balancer
- Amazon AWS - CloudFront
- Amazon AWS - Elastic Load Balancer
- Amazon AWS - Web Application Firewall (WAF)
- Bro - Bro
- CheckPoint - Firewall and VPN
- CheckPoint - URL Filtering
- Cisco Systems - ASA
- Cisco Systems - Firepower
- Cisco Systems - Ironport
- Cisco Systems - Meraki
- Cisco Systems - Umbrella
- Cloudflare - Logpush
- Dell - Firewall
- Forcepoint - Web Security
- Fortinet - Fortigate
- Google - Google Cloud Platform
- Juniper - SRX Series Firewall
- McAfee - Web Gateway
- Microsoft - Azure
- Microsoft - Graph Security API
- Microsoft - IIS
- Microsoft - Office 365
- Netskope - Security Cloud
- Palo Alto Networks - Next Generation Firewall
- Proofpoint - Targeted Attack Protection
- Sophos - UTM 9
- Squid - Squid Proxy
- Symantec - Proxy Secure Gateway
- Symantec - Web Security Service
- Zscaler - Firewall
- Zscaler - Nanolog Streaming Service
Origin | Field |
---|---|
Normalized Schema | device_hostname |
Normalized Schema | device_ip |
Normalized Schema | http_referer_alexaRank |
Normalized Schema | http_referer_possibleDynDns |
Normalized Schema | http_url_alexaRank |
Normalized Schema | http_url_possibleDynDns |
Normalized Schema | srcDevice_hostname |
Normalized Schema | srcDevice_ip |
Normalized Schema | user_username |