Forum Discussion

akshay25june's avatar
akshay25june
Copper Contributor
Aug 21, 2024

Any rule/query for detecting Dynamic DNS in sentinel

Hi Team,

 

Sentinel having any table or rule from where we can fetch dynamic DNS details as alert?

1 Reply

  • jdom's avatar
    jdom
    Copper Contributor

    Coupling ASIM DNS data with existing rules in the azure sentinel github repo may be helpful here:

    https://learn.microsoft.com/en-us/AZURE/sentinel/normalization-schema-dns

    https://github.com/Azure/Azure-Sentinel/tree/master/Detections/ASimDNS

Resources