{"id":"4153a907-2451-4e4f-a578-c52bb6881432","title":"Suspicious DNS Query with B64 Encoded String","description":"Detects suspicious DNS queries using base64 encoding","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2018-05-10","modified":"2022-10-09","tags":["attack.exfiltration","attack.t1048.003","attack.command-and-control","attack.t1071.004"],"technique_ids":["T1048.003","T1071.004"],"logsource":{"category":"dns"},"falsepositives":["Unknown"],"references":["https://github.com/krmaxwell/dns-exfiltration"],"source_path":"rules/network/dns/net_dns_susp_b64_queries.yml","source_sha256":"34bb92d59041475b8d8d26d14846865d697cc64f594cf3b16100f0daf8068b3e","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/network/dns/net_dns_susp_b64_queries.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Suspicious DNS Query with B64 Encoded String\nid: 4153a907-2451-4e4f-a578-c52bb6881432\nstatus: test\ndescription: Detects suspicious DNS queries using base64 encoding\nreferences:\n    - https://github.com/krmaxwell/dns-exfiltration\nauthor: Florian Roth (Nextron Systems)\ndate: 2018-05-10\nmodified: 2022-10-09\ntags:\n    - attack.exfiltration\n    - attack.t1048.003\n    - attack.command-and-control\n    - attack.t1071.004\nlogsource:\n    category: dns\ndetection:\n    selection:\n        query|contains: '==.'\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1048.003","id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","page":"techniques/enterprise/T1048.003/"},{"key":"enterprise/T1071.004","id":"T1071.004","name":"DNS","page":"techniques/enterprise/T1071.004/"}],"data_path":"data/detection-rules/4153a907-2451-4e4f-a578-c52bb6881432.json","kind":"sigma"}
