2012-02-24
04:48 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Example: Unapproved Internet DNS Queries
Attached is a correlation rule (the logic anyway) for alerting on internet bound DNS queries, which may be indicitive of malware or policy violation.
Keep in mind you may trigger lots of alerts initially. Customize as you need.
0 Replies
