network

Monero Crypto Coin Mining Pool Lookup
level
status stable

Detects suspicious DNS queries to Monero mining pools

Wannacry Killswitch Domain
level
status test

Detects wannacry killswitch domain dns queries

High TXT Records Requests Rate
level
status test

Extremely high rate of TXT record type DNS requests from host per short period of time. Possible result of Do-exfiltration tool execution

High NULL Records Requests Rate
level
status test

Extremely high rate of NULL record type DNS requests from host per short period of time. Possible result of iodine tool execution

High DNS Requests Rate
level
status experimental

High DNS requests amount from host per short period of time

High DNS Requests Rate
level
status experimental

High DNS requests amount from host per short period of time

High DNS Bytes Out
level
status experimental

High DNS queries bytes amount from host per short period of time

High DNS Bytes Out
level
status experimental

High DNS queries bytes amount from host per short period of time

Possible DNS Tunneling
level
status test

Normally, DNS logs contain a limited amount of different dns queries for a single domain. This rule detects a high amount of queries for a single domain, which can be an indicator that DNS is used to transfer data.

Suspicious DNS Query with B64 Encoded String
level
status experimental

Detects suspicious DNS queries using base64 encoding

Cobalt Strike DNS Beaconing
level
status experimental

Detects suspicious DNS queries known from Cobalt Strike beacons

Equation Group C2 Communication
level
status test

Detects communication to C2 servers mentioned in the operational notes of the ShadowBroker leak of EquationGroup C2 tools

Telegram Bot API Request
level
status experimental

Detects suspicious DNS queries to api.telegram.org used by Telegram Bots of any kind

Network Scans Count By Destination Port
level
status experimental

Detects many failed connection attempts to different ports or hosts

Network Scans Count By Destination IP
level
status test

Detects many failed connection attempts to different ports or hosts

DNS TXT Answer with Possible Execution Strings
level
status test

Detects strings used in command execution in DNS TXT Answer

cisco
Contains 1 rules/sub-categories
zeek
Contains 20 rules/sub-categories

Sponsored by

Phish Report logo
With Phish Report you can achieve streamlined phishing takedowns using your existing security team.