Document toolboxDocument toolbox

DNS detections

 

Microsoft has detected multiple 0-day exploits being used to attack on-premises versions of Microsoft Exchange Server in limited and targeted attacks.

Source table → domains.all

Detect a domain with a TLD, not in Mozilla TLD List.

Source table → domains.all

Unusual User Agent length detected. It can be associated with some type of attack or vulnerability.

Source table → domains.all

The REvil Ransomware has hit 40 service providers globally due to multiple Kaseya VSA Zero-days. the attack was pushed out via a infected IT Management update from Kaseya.

Source table → domains.all

Too long subdomains could be part of Application Layer Protocols.

Source table → network.dns