Skip to content

Latest commit

 

History

History
45 lines (38 loc) · 2.1 KB

LEGACY-S00026.md

File metadata and controls

45 lines (38 loc) · 2.1 KB

Rules: DNS Lookup of High Entropy Domain

Description

DNS lookup of a high entropy domain name, which may be indicative of a domain generation algorithm (DGA) related domain. This technique is described at https://attack.mitre.org/techniques/T1483/.

Additional Details

Detail Value
Type Match
Category Exfiltration
Apply Risk to Entities srcDevice_ip
Signal Name DNS Lookup of High Entropy Domain
Summary Expression High entropy domain: {{dns_queryDomain_rootDomain}}
Score/Severity Static: 2
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0010, _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1568, _mitreAttackTechnique:T1568.002

Vendors and Products

Fields Used

Origin Field
Normalized Schema dns_queryDomain_alexaRank
Normalized Schema dns_queryDomain_entropyRootDomain
Normalized Schema listMatches
Normalized Schema srcDevice_ip