Rules: DNS Lookup of High Entropy Domain
DNS lookup of a high entropy domain name, which may be indicative of a domain generation algorithm (DGA) related domain. This technique is described at https://attack.mitre.org/techniques/T1483/.
Detail | Value |
---|---|
Type | Match |
Category | Exfiltration |
Apply Risk to Entities | srcDevice_ip |
Signal Name | DNS Lookup of High Entropy Domain |
Summary Expression | High entropy domain: {{dns_queryDomain_rootDomain}} |
Score/Severity | Static: 2 |
Enabled by Default | True |
Prototype | False |
Tags | _mitreAttackTactic:TA0010, _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1568, _mitreAttackTechnique:T1568.002 |
- Amazon AWS - Application Load Balancer
- Amazon AWS - Route53
- Bro - Bro
- Cisco Systems - Umbrella
- Cloudflare - Logpush
- Fortinet - Fortigate
- Google - Google Cloud Platform
- Infoblox - Network Identity Operating System
- Microsoft - Azure
- Microsoft - DNS
- Microsoft - Windows
- Netskope - WebTx
- Sophos - UTM 9
- Zscaler - Firewall
- Zscaler - Nanolog Streaming Service
Origin | Field |
---|---|
Normalized Schema | dns_queryDomain_alexaRank |
Normalized Schema | dns_queryDomain_entropyRootDomain |
Normalized Schema | listMatches |
Normalized Schema | srcDevice_ip |