Skip to content

Latest commit

 

History

History
14 lines (12 loc) · 1 KB

r_m_cisco_cisco_Malware.md

File metadata and controls

14 lines (12 loc) · 1 KB

Rules by Product and UseCase

Vendor: Cisco

Product: Cisco

Use-Case: Malware

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
2 0 3 1 0
Event Type Rules Models
dns-response T1071 - Application Layer Protocol
A-DNS-MALDOM-RESPONSE: DNS query for blacklisted domain was successful from this asset
A-DNS-DGADOM-RESPONSE: DNS query for DGA domain was successful from this asset

T1568 - Dynamic Resolution
A-DNS-DGADOM-RESPONSE: DNS query for DGA domain was successful from this asset

T1568.002 - Dynamic Resolution: Domain Generation Algorithms
A-DNS-DGADOM-RESPONSE: DNS query for DGA domain was successful from this asset