Rules Contributing to DNS Query to TOR Proxy Domain
The following rules are used to identify DNS queries to onion domains and proxy domains for TOR network. Any one or more of these will trigger the DNS Query to TOR Proxy Domain Alert. Details for each rule can be viewed by clicking the More Details link in the description.
Title |
Description |
||||||||
---|---|---|---|---|---|---|---|---|---|
DNS Query to TOR Proxy Domain |
DNS query to onion domains and proxy domains for TOR network. More details
Rule IDQuery{'selection_domain': {'DnsQuestionName|endswith': ['.onion', '.tor2web.org', '.tor2web.com', '.torlink.co', '.onion.to', '.onion.ink', '.onion.cab', '.onion.nu', '.onion.link', '.onion.it', '.onion.city', '.onion.direct', '.onion.top', '.onion.casa', '.onion.plus', '.onion.rip', '.onion.dog', '.tor2web.fi', '.tor2web.blutmagie.de', '.onion.sh', '.onion.lu', '.onion.pet', '.t2w.pw', '.tor2web.ae.org', '.tor2web.io', '.tor2web.xyz', '.onion.lt', '.s1.tor-gateways.de', '.s2.tor-gateways.de', '.s3.tor-gateways.de', '.s4.tor-gateways.de', '.s5.tor-gateways.de', '.hiddenservice.net']}, 'condition': 'selection_domain'} Log SourceStellar Cyber Network Events configured. Rule SourceDeveloped internally by Stellar Cyber Tactics, Techniques, and ProceduresTA0010, T1048, TA0011, T1090.003 ReferencesSeverity30 Suppression Logic Based On
Additional Information
|