LoFP LoFP / legitimate dns queries and usage of mega

Techniques

Sample rules

DNS Query To MEGA Hosting Website

Description

Detects DNS queries for subdomains related to MEGA sharing website

Detection logic

condition: selection
selection:
  QueryName|contains: userstorage.mega.co.nz

DNS Query To MEGA Hosting Website - DNS Client

Description

Detects DNS queries for subdomains related to MEGA sharing website

Detection logic

condition: selection
selection:
  EventID: 3008
  QueryName|contains: userstorage.mega.co.nz