Outbound contact with a HoneyLabs malware loader or C2 URL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Looks for requests to URLs that HoneyLabs extracted from payloads captured by its honeypot sensors. These are the addresses attacker tooling actually fetched its second stage from, so a hit generally indicates post-compromise activity rather than inbound scanning and is worth investigating on the requesting host.

Attribute Value
Type Hunting Query
Solution HoneyLabs
ID 3c8b6e21-45af-4d90-8b17-9e2f7c1a4d55
Tactics CommandAndControl
Techniques T1105
Required Connectors ThreatIntelligenceTaxii
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CommonSecurityLog ✓ ✓ ✓
ThreatIntelIndicators ✓ ✓ ✗

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries · Back to HoneyLabs