Open hal308 opened 1 month ago
We would like to add the fields tld, parent domain, and subdomain to the dns query object so we can use those fields to differentiate between different parts of the domain. This is useful when looking for tunneling activity.
tld
parent domain
subdomain
query.tld query.parent query.subdomain
query.tld
query.parent
query.subdomain
May be related to https://github.com/ocsf/ocsf-schema/issues/1102
We would like to add the fields
tld
,parent domain
, andsubdomain
to the dns query object so we can use those fields to differentiate between different parts of the domain. This is useful when looking for tunneling activity.query.tld
query.parent
query.subdomain