Skip to content

Latest commit

 

History

History
41 lines (34 loc) · 1.89 KB

LEGACY-S00042.md

File metadata and controls

41 lines (34 loc) · 1.89 KB

Rules: HTTP Request to Domain in Non-Standard TLD

Description

HTTP request to a domain that is not under an ICANN-standard TLD. These TLDs are provided by alternate DNS root servers such as OpenNIC. Their use on corporate networks is fundamentally suspicious and potentially a sign of abuse by threat actors.

Additional Details

Detail Value
Type Match
Category Command and Control
Apply Risk to Entities srcDevice_ip
Signal Name HTTP Request to Domain in Non-Standard TLD
Summary Expression HTTP request from IP: {{srcDevice_ip}} to URL: {{http_url}}
Score/Severity Static: 6
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1071, _mitreAttackTechnique:T1071.001

Vendors and Products

Fields Used

Origin Field
Normalized Schema http_url_tld
Normalized Schema listMatches
Normalized Schema srcDevice_ip