Files
blue-team-tools/rules/linux/lnx_susp_named.yml
T

22 lines
632 B
YAML
Raw Normal View History

2018-02-20 14:56:28 +01:00
title: Suspicious Named Error
2019-11-12 23:12:27 +01:00
id: c8e35e96-19ce-4f16-aeb6-fd5588dc5365
2018-02-20 14:56:28 +01:00
status: experimental
2019-11-12 23:12:27 +01:00
description: Detects suspicious DNS error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
2018-02-20 14:56:28 +01:00
references:
- https://github.com/ossec/ossec-hids/blob/master/etc/rules/named_rules.xml
author: Florian Roth
date: 2018/02/20
logsource:
product: linux
service: syslog
detection:
keywords:
- '* dropping source port zero packet from *'
- '* denied AXFR from *'
- '* exiting (due to fatal error)*'
condition: keywords
falsepositives:
- Unknown
level: high