logo

Detecting Long Connections With Zeek/Bro and RITA

ID: 516ae7b6-dc4c-5dc3-8310-468c4efee601

STIX ID: report--516ae7b6-dc4c-5dc3-8310-468c4efee601

Feed Name: Black Hills Infosec Blog

Date Published: 2020-03-18

Date Updated: 2026-04-27

Author: BHIS

...
...

A tutorial demonstrates using Active Countermeasures’ RITA on the ADHD VM to identify DNS-based command-and-control (e.g., DNScat2) by detecting massive volumes of randomized subdomain queries (e.g., nanobotninjas.com) in Bro/Zeek DNS logs and RITA reports, including practical use of zgrep for compressed logs, while warning that such traffic often traverses Google’s 8.8.8.8—frequently whitelisted by organizations—reducing detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.