Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

query missing from "blacklisted dns answer" evidence #1111

Open
AlyaGomaa opened this issue Dec 10, 2024 · 0 comments
Open

query missing from "blacklisted dns answer" evidence #1111

AlyaGomaa opened this issue Dec 10, 2024 · 0 comments

Comments

@AlyaGomaa
Copy link
Collaborator

cmd: ./slips.py -e 1 -f dataset/test6-malicious.suricata.json -o a

Evidence: - Detected DNS answer with a blacklisted IP: 122.248.252.67 for query: Description: 1.2613571570498145e-05 Source: AIP_historical_blacklist_prioritized_by_newest_attackers.csv. threat level: medium.

@AlyaGomaa AlyaGomaa added this to Slips Dec 10, 2024
@AlyaGomaa AlyaGomaa converted this from a draft issue Dec 10, 2024
@AlyaGomaa AlyaGomaa moved this from Todo to Working on it in Slips Dec 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Working on it
Development

No branches or pull requests

1 participant