Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
'This rule makes use of the series decompose anomaly method to generate an alert when multiple clients report errors for the same DNS query. This rule monitors DNS traffic over a period of 14 days to detect possible similar C2 communication originating from different clients. It utilizes ASIM normalization and is applied to any source that supports the ASIM DNS schema. The rule also depends on the "DNSEssentialsCustomParser" Parser, so please make sure it is insta
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | DNS Essentials |
| ID | cf687598-5a2c-46f8-81c8-06b15ed489b1 |
| Severity | Medium |
| Status | Available |
| Kind | Scheduled |
| Tactics | CommandAndControl |
| Techniques | T1568, T1573, T1008 |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
Anomalies |
✓ | ✓ | ✓ |
DNS_Summarized_Logs_ipV1_CL 🔶 |
? | ✓ | ? |
DNS_Summarized_Logs_ip_CL 🔶 |
? | ✓ | ? |
DNS_Summarized_Logs_sourceInfoV1_CL 🔶 |
? | ✓ | ? |
DNS_Summarized_Logs_sourceInfo_CL 🔶 |
? | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊