New preview detection: Suspicious communication over DNS

%3CLINGO-SUB%20id%3D%22lingo-sub-267976%22%20slang%3D%22en-US%22%3ENew%20preview%20detection%3A%20Suspicious%20communication%20over%20DNS%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-267976%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20DNS%20protocol%20in%20many%20organizations%20is%20typically%20not%20monitored%20and%20is%20rarely%20blocked%20against%20malicious%20activity.%20%26nbsp%3BOpen%20DNS%20capabilities%20allow%20attackers%20on%20compromised%20machines%20to%20abuse%20the%20DNS%20protocol%20for%20malicious%20communication%20such%20as%20data%20exfiltration%2C%20command%20and%20control%2C%20and%20evading%20corporate%20network%20restrictions.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EStarting%20from%20Version%202.49%2C%20Azure%20ATP%20will%20detect%20attempts%20at%20%3CSTRONG%3E%3CEM%3ESuspicious%20Communication%20over%20DNS%3C%2FEM%3E%3C%2FSTRONG%3E%20and%20issue%20a%20security%20alert%20like%20the%20one%20shown%20below.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20more%20information%20visit%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2Fatasaguide-dnssus%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Faka.ms%2Fatasaguide-dnssus%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EStay%20tuned%20for%20additional%20alerts%20and%20updates.%20Your%20feedback%20is%20welcome%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20624px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F55723i1BCF8D1E11B63263%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22dns%20communication.jpg%22%20title%3D%22dns%20communication.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

The DNS protocol in many organizations is typically not monitored and is rarely blocked against malicious activity.  Open DNS capabilities allow attackers on compromised machines to abuse the DNS protocol for malicious communication such as data exfiltration, command and control, and evading corporate network restrictions.

 

Starting from Version 2.49, Azure ATP will detect attempts at Suspicious Communication over DNS and issue a security alert like the one shown below.

 

For more information visit https://aka.ms/atasaguide-dnssus

Stay tuned for additional alerts and updates. Your feedback is welcomedns communication.jpg

0 Replies