Skip to content

Latest commit

 

History

History
68 lines (61 loc) · 3.79 KB

MATCH-S00835.md

File metadata and controls

68 lines (61 loc) · 3.79 KB

Rules: Possible Dynamic URL Domain

Description

This rule looks for URL/refferer domains which appear to be associated with a dynamic DNS service.

Additional Details

Detail Value
Type Templated Match
Category Command and Control
Apply Risk to Entities device_hostname, device_ip, srcDevice_hostname, srcDevice_ip, user_username
Signal Name Possible Dynamic URL Domain
Summary Expression Possible dynamic DNS domain for URL: {{http_url_fqdn}}
Score/Severity Static: 1
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1568, _mitreAttackTechnique:T1568.001, _mitreAttackTechnique:T1568.002, _mitreAttackTechnique:T1568.003

Vendors and Products

Fields Used

Origin Field
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema http_referer_alexaRank
Normalized Schema http_referer_possibleDynDns
Normalized Schema http_url_alexaRank
Normalized Schema http_url_possibleDynDns
Normalized Schema srcDevice_hostname
Normalized Schema srcDevice_ip
Normalized Schema user_username