Explanation
- Group charts by
- Charts can be grouped by process, host, or process@host
- DNS risk patterns
- DNS requests are tested against common exfiltration and tunneling patterns (Source). DNS risk is the sum of all findings, displayed per entity and over time in the chart. Click on an entity to get a drilldown.
- Tested patterns
-
- > 52 chars: tests whether the DNS host name contains more than 52 chars.
- > 27 unique chars: tests whether the DNS host name contains more than 27 unique chars.
- No/empty response: tests whether the response is either not available or empty (e.g., SOA).
- TXT record: tests for the uncommon response type TXT.
- High entropy: tests the DNS request for high entropy based on Shannon entropy.