LoFP LoFP / t1048.003

t1048.003

TitleTags
false positives may be present if dns data exfiltration request look very similar to benign dns requests.
false positives will be present based on legitimate software, filtering may need to occur.
it's possible that an enterprise has more than five dns servers that are configured in a round-robin rotation. please customize the search, as appropriate.
it's possible that legitimate txt record responses can be long enough to trigger this search. you can modify the packet threshold for this search to help mitigate false positives.
it's possible that normal dns traffic will exhibit this behavior. if an alert is generated, please investigate and validate as appropriate. the threshold can also be modified to better suit your environment.
it's possible there can be long domain names that are legitimate.
legitimate script
legitimate usage of system.net.networkinformation.ping class
legitimate usage of wget utility to post a file
network admin and normal user may send this file attachment as part of their day to day work. having a good protocol in attaching this file type to an e-mail may reduce the risk of having a spear phishing attack.
none identified
normal archive transfer via http protocol may trip this detection.
other smtp tools