CriticalPathSecurity / Zeek-Intelligence-Feeds

Zeek-Formatted Threat Intelligence Feeds
MIT License
346 stars 46 forks source link

False positive #5

Closed aziel12 closed 2 years ago

aziel12 commented 3 years ago

Hello, I have found www.amazon.com and www.youtube.com being flagged as cobaltstrike domains. Is it false positive? What does meta.do_notice mean, in all intel files they are F. Thanks source in: cps_cobaltstrike_domain.intel

www.youtube.com Intel::DOMAIN CobaltStrike F C2 amazon.com Intel::DOMAIN CobaltStrike F C2

Patrick-Kelley commented 2 years ago

Apologies for just seeing this.

Yes, the feed that included that artifact has a high-rate for false positives. I've commented out the line that spins it up. I'll work on a better solution in coming days.