INDICATOR-COMPROMISE Suspicious .tk dns query

Shawn Welnak via Snort-users <[email protected]> Thu, 23 May 2024 19:37:27 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <NgXMHWxCfeWUL-V5qVAfoNv2Hch-3qfpDhCqukaVGQlK0ysPhYwL3pOt6Z_FyzVM20mslGPrATA5iTVwXVynhTgk6-jXkM4yoCtvclBrs0Q=@proton.me>
Hello: I have Snort working fairly well (new user), but am struggling a bit with distinguishing false positives, and how to respond to them for logs. I'm hoping assistance with just a single examples will set me right. The information about the alert, as given in pfSense:

Pri Proto Class Source IP SPort Dest. IP DPort GID:SID

3 UDP Misc activity [my public IP] 19766 149.112.112.112 53 1:39867

Description

INDICATOR-COMPROMISE Suspicious .tk dns query

First, I cannot figure why a DNS lookup from my public IP to Quad9 (as set by me on DNS server) would generate an alert.
Second, can I suppress this alertjust forthis particular Quad9 lookup, without suppressing the entire alert itself? (I.e., I have figured out how to suppress a an alert in general).
Thank you.

Sent with [Proton Mail](https://proton.me/) secure email.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette