This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
DNS-over-HTTPS Enabled by Registry
Original Source:
[Sigma source]
Title:
DNS-over-HTTPS Enabled by Registry
Status:
test
Description:
Detects when a user enables DNS-over-HTTPS. This can be used to hide internet activity or be used to hide the process of exfiltrating data. With this enabled organization will lose visibility into data such as query type, response and originating IP that are used to determine bad actors.
References:
-https://www.tenforums.com/tutorials/151318-how-enable-disable-dns-over-https-doh-microsoft-edge.html
-https://github.com/elastic/detection-rules/issues/1371
-https://chromeenterprise.google/policies/?policy=DnsOverHttpsMode
-https://admx.help/HKLM/Software/Policies/Mozilla/Firefox/DNSOverHTTPS
Author:
Austin Songer
Date:
2021-07-22
modified:
2023-08-17
Tags:
-'attack.persistence'
-'attack.stealth'
-'attack.defense-impairment'
-'attack.t1140'
-'attack.t1112'
Logsource:
product: windows
category: registry_set
Detection:
selection_edge:
TargetObject|endswith
:
'\SOFTWARE\Policies\Microsoft\Edge\BuiltInDnsClientEnabled'
Details
:
'DWORD (0x00000001)'
selection_chrome:
TargetObject|endswith
:
'\SOFTWARE\Google\Chrome\DnsOverHttpsMode'
Details
:
'secure'
selection_firefox:
TargetObject|endswith
:
'\SOFTWARE\Policies\Mozilla\Firefox\DNSOverHTTPS\Enabled'
Details
:
'DWORD (0x00000001)'
condition
:
1 of selection_*
Falsepositives:
-Unlikely
Level:
medium