Infoblox
Telemetry Evidence
These values show how indexed rules identify Infoblox telemetry.Kusto
Infoblox Infoblox_dnsclient InfobloxCDC InfobloxCDC_SOCInsights InfobloxInsight
Detection Rules
Kusto #
- Excessive NXDOMAIN DNS Queries source medium: 'This creates an incident in the event a client generates excessive amounts of DNS queries for non-existent domains.'
T1008,T1568 - Infoblox - Data Exfiltration Attack source medium: 'Data exfiltration attack detected by Infoblox Threat Insight. Customize query count, scheduling, responses and more. This rule depends on a parser based on a Kusto Function to work as expected called InfobloxCDC.'
T1498,T1565 - Infoblox - High Threat Level Query Not Blocked Detected source medium: 'At least 1 high threat level query generated by single host in 1 hour that is not blocked or redirected. Customize query count, scheduling, responses and more. This rule depends on a parser based on a Kusto Function to work as expected called InfobloxCDC.'
T1498,T1565 - Infoblox - IQ for TD Detected Insights - API Source source medium: 'Infoblox IQ for TD Insight detected in logs sourced via REST API. Customize scheduling, responses and more. This rule depends on a parser based on a Kusto Function to work as expected called InfobloxInsight.'
T1498,T1565 - Infoblox - IQ for TD Insight Detected - CDC Source source medium: 'Infoblox IQ for Threat Defense Insight detected in logs sourced via Infoblox CDC. Customize scheduling, responses and more. This rule depends on a parser based on a Kusto Function to work as expected called InfobloxCDC_SOCInsights.'
T1498,T1565 - Infoblox - Many High Threat Level Queries From Single Host Detected source medium: 'At least 200 high threat level queries generated by single host in 1 hour. Queries do not need to be the same. Customize query count, scheduling, responses and more. This rule depends on a parser based on a Kusto Function to work as expected called InfobloxCDC.'
T1498,T1565 - Infoblox - Many High Threat Level Single Query Detected source medium: 'Single high threat level domain queried at least 200 times in 1 hour regardless of source. Customize query count, scheduling, responses and more. This rule depends on a parser based on a Kusto Function to work as expected called InfobloxCDC.'
T1498,T1565 - Infoblox - Many NXDOMAIN DNS Responses Detected source medium: 'Detected at least 200 DNS responses for non-existent domains in 1 hour generated by single host. Queries do not need to be the same. Customize query count, scheduling, responses and more. This rule depends on a parser based on a Kusto Function to work as expected called InfobloxCDC.'
T1498,T1565 - Infoblox - SOC Insight Detected - API Source source medium: 'Infoblox SOC Insight detected in logs sourced via REST API. Customize scheduling, responses and more. This rule depends on a parser based on a Kusto Function to work as expected called InfobloxInsight.'
T1498,T1565 - Infoblox - SOC Insight Detected - CDC Source source medium: 'Infoblox SOC Insight detected in logs sourced via Infoblox CDC. Customize scheduling, responses and more. This rule depends on a parser based on a Kusto Function to work as expected called InfobloxCDC_SOCInsights.'
T1498,T1565
Show 2 more
- Infoblox - TI - InfobloxCDC Match Found - Lookalike Domains source medium: 'InfobloxCDC Lookalike Domain match found in your Infoblox TIDE Threat Intelligence. Customize query count, scheduling, responses and more. Modify data sources, types and threat properties as desired. This rule depends on a parser based on a Kusto Function to work as expected called InfobloxCDC.'
T1498,T1565 - Potential DHCP Starvation Attack source medium: 'This creates an incident in the event that an excessive amount of DHCPREQUEST have been recieved by a DHCP Server and could potentially be an indication of a DHCP Starvation Attack.'
T1200
Compatible Rules
These rules declare Infoblox connector or schema compatibility without a product-specific query filter.Kusto #
T1496T1048T1008, T1568T1071T1008, T1568T1071T1071T1071T1071
Package-Only Rules
These rules appear in the Infoblox Sentinel solution, but their queries do not identify Infoblox telemetry. They do not count toward Rules.Kusto #
T1498, T1565T1498, T1565