Techniques
Sample rules
Telegram API Access
- source: sigma
- technicques:
- t1071
- t1071.001
- t1102
- t1102.002
Description
Detects suspicious requests to Telegram API without the usual Telegram User-Agent
Detection logic
condition: selection and not filter
filter:
c-useragent|contains:
- Telegram
- Bot
selection:
cs-host: api.telegram.org
Telegram Bot API Request
- source: sigma
- technicques:
- t1102
- t1102.002
Description
Detects suspicious DNS queries to api.telegram.org used by Telegram Bots of any kind
Detection logic
condition: selection
selection:
query: api.telegram.org