Elastic low stable kql

Uncommon DNS Request via Bun or Node.js

This rule detects uncommon DNS requests via Bun or Node.js. Adversaries may leverage these tools via a supply chain attack of a compromised developer's package to execute malicious code and steal/exfiltrate data.

View Source

Detection Logic

event.category:network and host.os.type:(linux or macos or windows) and event.action:lookup_requested and
process.name:(bun or bun.exe or node or node.exe or nodejs) and dns.question.name:(* and not localhost)

Field Validations

Loading…

Comments (0)

Loading comments...