Detecting Long Connections With Zeek/Bro and RITA
ID: 516ae7b6-dc4c-5dc3-8310-468c4efee601
STIX ID: report--516ae7b6-dc4c-5dc3-8310-468c4efee601
Feed Name: Black Hills Infosec Blog
A tutorial demonstrates using Active Countermeasures’ RITA on the ADHD VM to identify DNS-based command-and-control (e.g., DNScat2) by detecting massive volumes of randomized subdomain queries (e.g., nanobotninjas.com) in Bro/Zeek DNS logs and RITA reports, including practical use of zgrep for compressed logs, while warning that such traffic often traverses Google’s 8.8.8.8—frequently whitelisted by organizations—reducing detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
