INDICATOR-COMPROMISE Suspicious .tk dns query
Shawn Welnak via Snort-users <[email protected]> Thu, 23 May 2024 19:37:27 +0000
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <NgXMHWxCfeWUL-V5qVAfoNv2Hch-3qfpDhCqukaVGQlK0ysPhYwL3pOt6Z_FyzVM20mslGPrATA5iTVwXVynhTgk6-jXkM4yoCtvclBrs0Q=@proton.me> |
Hello: I have Snort working fairly well (new user), but am struggling a bit with distinguishing false positives, and how to respond to them for logs. I'm hoping assistance with just a single examples will set me right. The information about the alert, as given in pfSense: Pri Proto Class Source IP SPort Dest. IP DPort GID:SID 3 UDP Misc activity [my public IP] 19766 149.112.112.112 53 1:39867 Description INDICATOR-COMPROMISE Suspicious .tk dns query First, I cannot figure why a DNS lookup from my public IP to Quad9 (as set by me on DNS server) would generate an alert. Second, can I suppress this alertjust forthis particular Quad9 lookup, without suppressing the entire alert itself? (I.e., I have figured out how to suppress a an alert in general). Thank you. Sent with [Proton Mail](https://proton.me/) secure email. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette