# DNS Check Malware

**URL:** <https://discuss.elastic.co/t/dns-check-malware/238019>\
**Category:** SIEM\
**Created:** [June 22, 2020, 7:06am UTC](https://discuss.elastic.co/t/dns-check-malware/238019 "2020-06-22T07:06:33Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![nurhambali](https://avatars.discourse-cdn.com/v4/letter/n/3ec8ea/32.png) [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Post date:** [June 22, 2020, 7:06am UTC](https://discuss.elastic.co/t/dns-check-malware/238019/1 "2020-06-22T07:06:34Z")

</div>

hi all,

how to separate package dns request malware and bitcoin polling in SIEM ?

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [June 22, 2020, 7:17am UTC](https://discuss.elastic.co/t/dns-check-malware/238019/2 "2020-06-22T07:17:58Z")

</div>

Hi,

How are you receiving these logs? Are you using the Elastic endpoint to collect this data or are relying on an IDS & Proxy implementation?

---

<div class="post-metadata">

**Author:** ![nurhambali](https://avatars.discourse-cdn.com/v4/letter/n/3ec8ea/32.png) [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Post date:** [June 22, 2020, 7:24am UTC](https://discuss.elastic.co/t/dns-check-malware/238019/3 "2020-06-22T07:24:32Z")

</div>

I send packetbeat to elastic and I want to separate the malware domain in SIEM,

can you do it this way?

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [June 22, 2020, 7:32am UTC](https://discuss.elastic.co/t/dns-check-malware/238019/4 "2020-06-22T07:32:29Z")

</div>

Oh, I see! So, a static lookup against a set of domains that you mention?

Yes, it should be possible. You can create signals for your query and then observe triggers if any. Have a look at the signal to detect [IRC activity to the internet](https://demo.elastic.co/app/siem#/detections/rules/id/9d5d1974-43e2-4f89-902f-f2c62a2f1267?timerange=(global:(linkTo:!(timeline),timerange:(from:1592724556421,fromStr:now-24h,kind:relative,to:1592810956422,toStr:now)),timeline:(linkTo:!(global),timerange:(from:1592724556421,fromStr:now-24h,kind:relative,to:1592810956422,toStr:now)))).

---

<div class="post-metadata">

**Author:** ![nurhambali](https://avatars.discourse-cdn.com/v4/letter/n/3ec8ea/32.png) [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Post date:** [June 22, 2020, 7:43am UTC](https://discuss.elastic.co/t/dns-check-malware/238019/5 "2020-06-22T07:43:57Z")

</div>

Detection rule alerting SIEM not runing in the elastic subscriptions opensource ?

is there any other way ?

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [June 22, 2020, 7:47am UTC](https://discuss.elastic.co/t/dns-check-malware/238019/6 "2020-06-22T07:47:39Z")

</div>

Yes! Use the API to query data, in a scheduled manner and then perform alerting through an external API integration.

You could also look at some [third-party libraries](https://elastalert.readthedocs.io/en/latest/). Everything including Elastic SIEM has it's limitations. You could decide, what is acceptable and work on it.

---

<div class="post-metadata">

**Author:** ![nurhambali](https://avatars.discourse-cdn.com/v4/letter/n/3ec8ea/32.png) [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Post date:** [June 22, 2020, 7:50am UTC](https://discuss.elastic.co/t/dns-check-malware/238019/7 "2020-06-22T07:50:24Z")

</div>

Thank you I will try to use elastic alerts to do domain detection 😀

---

<div class="post-metadata">

**Author:** ![zkhanfur](https://avatars.discourse-cdn.com/v4/letter/z/97f17d/32.png) [@zkhanfur](https://discuss.elastic.co/u/zkhanfur)\
**Post date:** [July 6, 2020, 6:12am UTC](https://discuss.elastic.co/t/dns-check-malware/238019/8 "2020-07-06T06:12:08Z")

</div>

We have found something similar for DHCP here [https://zeglory.com/monitoring-dhcp-using-elk/](https://zeglory.com/monitoring-dhcp-using-elk/) but would be very interested in getting this for DNS as well. Could you kindly share something describing the solution in details?

---

<div class="post-metadata">

**Author:** ![zkhanfur](https://avatars.discourse-cdn.com/v4/letter/z/97f17d/32.png) [@zkhanfur](https://discuss.elastic.co/u/zkhanfur)\
**Post date:** [July 6, 2020, 6:12am UTC](https://discuss.elastic.co/t/dns-check-malware/238019/9 "2020-07-06T06:12:46Z")

</div>

> [@zkhanfur](#):
>
> We have found something similar for DHCP here [https://zeglory.com/monitoring-dhcp-using-elk/](https://zeglory.com/monitoring-dhcp-using-elk/) but would be very interested in getting this for DNS as well. Could you kindly share something describing the solution in details?

We have found something similar for DHCP here [https://zeglory.com/monitoring-dhcp-using-elk/](https://zeglory.com/monitoring-dhcp-using-elk/) but would be very interested in getting this for DNS as well. Could you kindly share something describing the solution in details?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2020, 6:12am UTC](https://discuss.elastic.co/t/dns-check-malware/238019/10 "2020-08-03T06:12:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
