Seeing (Sig)Red
ID: 258cc2dd-f554-51d9-8c38-79e903a2f570
STIX ID: report--258cc2dd-f554-51d9-8c38-79e903a2f570
Feed Name: SensePost Blog
Threat Score
This post documents detection techniques for CVE-2020-1350 (SigRed), describing the DNS packet characteristics used by the exploit and providing multiple Suricata IDS rules to detect and correlate exploitation attempts, insider queries, and victim behavior, along with testing notes and rule tuning to reduce false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
