rcfontana / ThreatHuntingProcess

A transparent Threat Hunting Process that can be followed and adapted to your organization.
2 stars 0 forks source link

RF_SuspiciousTLDs_Proxy_0521 #1

Open rcfontana opened 3 years ago

rcfontana commented 3 years ago

I had this idea that we could monitor weirdness in our network by checking proxy connections to poor reputation TLDs. Besides that, matching on some specific extensions would also be interesting.

Example.: GET request to some .party with request_url: .bin

SpamHaus - Reference

rcfontana commented 2 years ago

There's a SIGMA rule on that same level for proxy logs! https://github.com/SigmaHQ/sigma/blob/master/rules/proxy/proxy_download_susp_tlds_blacklist.yml