Suspicious Domain Communication followed by Malware Activity

Suspicious Domain Communication followed by Malware Activity

Description

This threat is generated when a suspicious domain or IP address is visited by a user; after which that user or device starts to display "malware like" activity.

Content Mapping

This content is not mapped to any local saved search. Add mapping


Use Case

Advanced Threat Detection, Security Monitoring

Category

Adversary Tactics, Endpoint Compromise, Insider Threat, Malware

Alert Volume

Low

Data Availability

Bad

Journey

Stage 4

Data Sources

Network Communication
Host-based IDS
IDS or IPS
Endpoint Detection and Response
Authentication
Windows Security
Web Proxy
Anti-Virus or Anti-Malware
DNS
DLP
Email