Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This rule makes use of the series decompose anomaly method to generate an alert when client requests excessive amount of DNS queries to non-existent domains. This helps in identifying possible C2 communications. It utilizes ASIM normalization and is applied to any source that supports the ASIM DNS schema. The rule also depends on the "DNSEssentialsCustomParser" Parser, so please make sure it is installed and configured before you use this Rule.
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | DNS Essentials |
| ID | 02f23312-1a33-4390-8b80-f7cd4df4dea0 |
| Severity | Medium |
| Status | Available |
| Kind | Scheduled |
| Tactics | CommandAndControl |
| Techniques | T1568, T1008 |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
Anomalies |
✓ | ✓ | ✓ |
DNS_Summarized_Logs_ipV1_CL 🔶 |
? | ✓ | ? |
DNS_Summarized_Logs_ip_CL 🔶 |
? | ✓ | ? |
DNS_Summarized_Logs_sourceInfoV1_CL 🔶 |
? | ✓ | ? |
DNS_Summarized_Logs_sourceInfo_CL 🔶 |
? | ✓ | ? |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊