ET MALWARE Suspected Cobalt Strike Beacon Activity (DNS)
Query · suricata
threshold:type both, track by_src, count 3, seconds 5;
dns.query;
pcre:"/^[a-z0-9]{32}/";
content:".defenderupdateav.com"; endswith; fast_pattern;
threshold:type both, track by_src, count 3, seconds 5;
dns.query;
pcre:"/^[a-z0-9]{32}/";
content:".defenderupdateav.com"; endswith; fast_pattern;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.