Project

General

Profile

Actions

Feature #4515

closed

Add DNS logging of Z flag

Added by Odin Jenseg over 3 years ago. Updated almost 3 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Protocol, Rust

Description

The this Z field is logged by Zeek: https://docs.zeek.org/en/master/logs/dns.html
And has shown good value to have in investigations, and there has been created a sigma rule that is based on this flag:
https://github.com/SigmaHQ/sigma/blob/master/rules/network/zeek/zeek_dns_suspicious_zbit_flag.yml

I think this should be pretty strightforward, so I will great a PR


Related issues 1 (0 open1 closed)

Related to Suricata - Bug #4924: dns: transaction not created when z-bit setClosedJason IshActions
Actions #2

Updated by Jason Ish almost 3 years ago

  • Related to Bug #4924: dns: transaction not created when z-bit set added
Actions #3

Updated by Jason Ish almost 3 years ago

  • Status changed from New to In Review
Actions #4

Updated by Jason Ish almost 3 years ago

  • Status changed from In Review to Closed
  • Target version set to 7.0.0-beta1

PR merged.

Actions

Also available in: Atom PDF