Possible FIN7 DGA Command and Control Behavior

This rule detects a known command and control pattern in network events. The FIN7 threat group is known to use this command and control technique, while maintaining persistence in their target's network.

Rule type: esql
Rule indices:

Rule Severity: high
Risk Score: 73
Runs every:
Searches indices from: now-9m
Maximum alerts per execution: 100
References:

Tags:

  • Use Case: Threat Detection
  • Tactic: Command and Control
  • Domain: Endpoint
  • Rule Type: ESQL
  • Data Source: PAN-OS
  • Resources: Investigation Guide

Version: 112
Rule authors:

  • Elastic

Rule license: Elastic License v2

In the event this rule identifies benign domains in your environment, the destination.domain exclusion in the rule can be modified to include those domains. Example: ... | where destination.domain not in ("zoom.us", "benign.domain1", "benign.domain2").

from packetbeat-*, filebeat-*, logs-network_traffic.*, logs-panw.panos* metadata _id, _version, _index
| where (
    data_stream.dataset in ("network_traffic.tls", "network_traffic.http") or
    (
      data_stream.dataset == "panw.panos" and
      network.application in ("ssl", "web-browsing") and network.transport == "tcp"
    ) or
    (event.category in ("network", "network_traffic") and network.protocol in ("tls", "http") and network.transport == "tcp")
  )
| where destination.domain RLIKE "[a-zA-Z]{4,5}\\.(pw|us|club|info|site|top)"
| where destination.domain != "zoom.us"
| keep @timestamp, destination.domain, source.ip, destination.ip, network.protocol, network.transport, data_stream.dataset, _id, _version, _index
		

Framework: MITRE ATT&CK