mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update detect_dga_domains_using_pretrained_model_in_dsdl.yml
This commit is contained in:
+3
-3
@@ -32,7 +32,7 @@ tags:
|
||||
- Suspicious DNS Traffic
|
||||
- Dynamic DNS
|
||||
- Command and Control
|
||||
asset_type: Web Server
|
||||
asset_type: Endpoint
|
||||
cis20:
|
||||
- CIS 8
|
||||
- CIS 12
|
||||
@@ -44,7 +44,7 @@ tags:
|
||||
impact: 70
|
||||
kill_chain_phases:
|
||||
- Command & Control
|
||||
message: A potentially a DGA domain $domain$ was detected from host $src$, kindly review.
|
||||
message: A potential connection to a DGA domain $domain$ was detected from host $src$, kindly review.
|
||||
mitre_attack_id:
|
||||
- T1568.002
|
||||
nist:
|
||||
@@ -54,7 +54,7 @@ tags:
|
||||
- DE.CM
|
||||
observable:
|
||||
- name: domain
|
||||
type: Other
|
||||
type: URL Domain
|
||||
role:
|
||||
- Attacker
|
||||
- name: src
|
||||
|
||||
Reference in New Issue
Block a user