{"id":"d59d7842-9a21-4bc6-ba98-64bfe0091355","title":"Powershell DNSExfiltration","description":"DNSExfiltrator allows for transferring (exfiltrate) a file over a DNS request covert channel","author":"frack113","status":"test","level":"high","date":"2022-01-07","modified":"","tags":["attack.exfiltration","attack.t1048"],"technique_ids":["T1048"],"logsource":{"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"},"falsepositives":["Legitimate script"],"references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1048/T1048.md#atomic-test-3---dnsexfiltration-doh","https://github.com/Arno0x/DNSExfiltrator"],"source_path":"rules/windows/powershell/powershell_script/posh_ps_invoke_dnsexfiltration.yml","source_sha256":"6512497a3cc7ed82ef8543454d5fdd9c83835df7ad0a403acf2550ff10a62b2a","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/powershell/powershell_script/posh_ps_invoke_dnsexfiltration.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Powershell DNSExfiltration\nid: d59d7842-9a21-4bc6-ba98-64bfe0091355\nstatus: test\ndescription: DNSExfiltrator allows for transferring (exfiltrate) a file over a DNS request covert channel\nreferences:\n    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1048/T1048.md#atomic-test-3---dnsexfiltration-doh\n    - https://github.com/Arno0x/DNSExfiltrator\nauthor: frack113\ndate: 2022-01-07\ntags:\n    - attack.exfiltration\n    - attack.t1048\nlogsource:\n    product: windows\n    category: ps_script\n    definition: 'Requirements: Script Block Logging must be enabled'\ndetection:\n    selection_cmdlet:\n        - ScriptBlockText|contains: 'Invoke-DNSExfiltrator'\n        - ScriptBlockText|contains|all:\n              - ' -i '\n              - ' -d '\n              - ' -p '\n              - ' -doh '\n              - ' -t '\n    condition: selection_cmdlet\nfalsepositives:\n    - Legitimate script\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1048","id":"T1048","name":"Exfiltration Over Alternative Protocol","page":"techniques/enterprise/T1048/"}],"data_path":"data/detection-rules/d59d7842-9a21-4bc6-ba98-64bfe0091355.json","kind":"sigma"}
