-
Notifications
You must be signed in to change notification settings - Fork 528
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Tuning] Connection to Commonly Abused Web Services #3425
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Will this not end up generating too much noise? For example,mail.*
will generate many hits given that for example gmail leverages mail.google.com
.
Do we wish to alert on all public IP discovery events? If so, do we think that should be part of the "commonly abused web services" rule, or should we create a new discovery rule such as "Public IP Discovery"?
Or would it make sense to turn this one into a BBR, and run a new_terms rule on top of it, for previously unknown dns entries?
removed mail services from rule scope
removed public IP discovery websvc
|
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
* Update command_and_control_common_webservices.toml * Update command_and_control_common_webservices.toml --------- Co-authored-by: Ruben Groenewoud <[email protected]> (cherry picked from commit 6917387)
extended list of dn.question.name web services.