travisbgreen/hunting-rules

Can we have rule for dnscat2 please

Jackson-Pollock opened this issue · 3 comments

Can we have rule for dnscat2 please

Can you provide PCAP? email to travis at travisgreen.net pls

Sorry for the delay in response. Emailed pcap.

Oops, added this some time ago and forgot to close this issue:
02/22/2022-02:18:38.749061 [**] [1:2610812:1] TGI HUNT dnscat in DNS Query [**] [Classification: Potentially Bad Traffic] [Priority: 2] {UDP} 192.168.30.10:49409 -> 192.168.30.20:53
Thank you @Jackson-Pollock