Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Matches active Datazag impersonation indicators against DNS activity normalized by the ASIM Dns schema, so the rule works across any normalized DNS source without modification. A match means a host inside the estate resolved a domain Datazag scored as brand impersonation, platform impersonation or attacker infrastructure. Requires the ASIM DNS parsers.
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Datazag |
| ID | 8f3c1a4e-6b52-4d19-9c07-2a5e8d0f7b41 |
| Severity | High |
| Status | Available |
| Kind | Scheduled |
| Tactics | InitialAccess, CommandAndControl |
| Techniques | T1566, T1071 |
| Required Connectors | ThreatIntelligenceTaxii |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
ThreatIntelIndicators |
✓ | ✓ | ✗ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊