🐾 - 🔔 Potential DNS Exfiltration 🥷 - T1048

SID: 3321447Rev: 8163 views
History
Sourcepawpatrules
CreatedMay 31, 2025
UpdatedSeptember 25, 2025
Classificationtrojan-activity
alert dns any any -> any any (msg:"🐾 - 🔔 Potential DNS Exfiltration 🥷 - T1048"; dns_query; flow:to_server, stateless; threshold:type threshold, track by_src, count 10, seconds 30; content:"."; pcre:"/^(?=[a-zA-Z0-9+=]{15,})(?![a-zA-Z0-9+=-]*-)[a-zA-Z0-9+=]{15,}.[a-zA-Z0-9.]{1,}.[a-zA-Z]{2,7}$/"; content:!".googleapis.com"; endswith; content:!".azureedge.net"; endswith; content:!".office.com"; endswith; content:!".azure.com"; endswith; content:!".sentry.io"; endswith; reference:url,https://attack.mitre.org/techniques/T1048/; metadata:created_at 2025_05_31, updated_at 2025_09_25, signature_severity Major, attack_target Client_and_Server, mitre_tactic_id TA0010, mitre_tactic_name Exfiltration, mitre_technique_id T1048, mitre_technique_name Exfiltration_Over_Alternative_Protocol; sid:3321447; rev:8; classtype:trojan-activity;)

Metadata

created at2025_05_31
updated at2025_09_25
signature severityMajor
attack targetClient_and_Server
mitre tactic idTA0010
mitre tactic nameExfiltration
mitre technique idT1048
mitre technique nameExfiltration_Over_Alternative_Protocol

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!