Home page logo

snort logo Snort mailing list archives

External DNS response
From: James Lay <jlay () slave-tothe-box net>
Date: Fri, 19 Apr 2013 12:12:22 -0600

Bot suspension technique:

alert udp $EXTERNAL_NET 53 -> $DNS_SERVERS any (msg:"INDICATOR-COMPROMISE External DNS response, possible bot 
suspension"; flow:from_server; content:""; fast_pattern:only; metadata:impact_flag red, service dns; 
classtype:trojan-activity; sid:10000048; rev:1;)

Precog is a next-generation analytics platform capable of advanced
analytics on semi-structured data. The platform includes APIs for building
apps and a phenomenal toolset for data science. Developers can use
our toolset for easy data analysis & visualization. Get a free account!
Snort-sigs mailing list
Snort-sigs () lists sourceforge net

Please visit http://blog.snort.org for the latest news about Snort!

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]